www.delorie.com/archives/browse.cgi   search  
Mail Archives: cygwin/2009/09/10/07:21:25

X-Recipient: archive-cygwin AT delorie DOT com
X-SWARE-Spam-Status: No, hits=-1.1 required=5.0 tests=AWL,BAYES_00,J_CHICKENPOX_42
X-Spam-Check-By: sourceware.org
Reply-To: <michael DOT parker AT st DOT com>
From: Michael PARKER <michael DOT parker AT st DOT com>
To: <gchicares AT sbcglobal DOT net>, <dave DOT korn DOT cygwin AT googlemail DOT com>
Cc: <cygwin AT cygwin DOT com>
Subject: Re: Re: setup.exe hijacked?
Date: Thu, 10 Sep 2009 12:21:01 +0100
Message-ID: <DDAA997052E840A9A8B3253AFAEB3D12@st.com>
MIME-Version: 1.0
Mailing-List: contact cygwin-help AT cygwin DOT com; run by ezmlm
List-Id: <cygwin.cygwin.com>
List-Subscribe: <mailto:cygwin-subscribe AT cygwin DOT com>
List-Archive: <http://sourceware.org/ml/cygwin/>
List-Post: <mailto:cygwin AT cygwin DOT com>
List-Help: <mailto:cygwin-help AT cygwin DOT com>, <http://sourceware.org/ml/#faqs>
Sender: cygwin-owner AT cygwin DOT com
Mail-Followup-To: cygwin AT cygwin DOT com
Delivered-To: mailing list cygwin AT cygwin DOT com

Greg, Dave,

A repeat of my activities earlier (file download via IE8 *and* wget) shows =
the problem to have now gone away.

I've still got a copy of the "bad" file - same file size as the "good" setu=
p.exe but with a earlier timestamp:

-rwx------+  1 585728 Aug  5  2008 setup.exe_bad*
-rwx------+  1 585728 Sep 10 11:56 setup.exe*=20

A "file" (OK, not difficult to fool) shows both to be:

MS-DOS executable PE  for MS Windows (GUI) Intel 80386 32-bit, UPX compress=
ed

---

A browser hijack is possible (and something I'll look into), although the f=
act I'm now able to download without problem (via both IE8 and wget) sugges=
ts otherwise. I've not rebooted in the meantime and besides, a download via=
 wget was giving the same problem earlier. This latter observation may be e=
xplained by local proxy caching, though.

The fact that the "bad" setup.exe crashed when executed suggests it might b=
e corrupted in some way. Could some form of proxy issue result in transient=
 data from two independent sources (the genuine setup.exe plus some transie=
nt "ebuddy" traffic) being merged into a single file?

Interestingly, I see multiple WinXP crash dialogs when attmpting to run the=
 "bad" executable. Not something I've seen with other crashing applications=
 before.=20

If either of you guys are sufficiently interested, I can send over a gzip'e=
d copy of the bad file.

Thanks for the interest,

Mike





--
Problem reports:       http://cygwin.com/problems.html
FAQ:                   http://cygwin.com/faq/
Documentation:         http://cygwin.com/docs.html
Unsubscribe info:      http://cygwin.com/ml/#unsubscribe-simple

- Raw text -


  webmaster     delorie software   privacy  
  Copyright © 2019   by DJ Delorie     Updated Jul 2019