X-Recipient: archive-cygwin@delorie.com
X-SWARE-Spam-Status: No, hits=-1.1 required=5.0 	tests=AWL,BAYES_00,J_CHICKENPOX_42
X-Spam-Check-By: sourceware.org
Reply-To: <michael.parker@st.com>
From: Michael PARKER <michael.parker@st.com>
To: <gchicares@sbcglobal.net>, <dave.korn.cygwin@googlemail.com>
Cc: <cygwin@cygwin.com>
Subject: Re: Re: setup.exe hijacked?
Date: Thu, 10 Sep 2009 12:21:01 +0100
Message-ID: <DDAA997052E840A9A8B3253AFAEB3D12@st.com>
MIME-Version: 1.0
Content-Type: text/plain; 	charset="utf-8"
Content-Transfer-Encoding: quoted-printable
Mailing-List: contact cygwin-help@cygwin.com; run by ezmlm
List-Id: <cygwin.cygwin.com>
List-Subscribe: <mailto:cygwin-subscribe@cygwin.com>
List-Archive: <http://sourceware.org/ml/cygwin/>
List-Post: <mailto:cygwin@cygwin.com>
List-Help: <mailto:cygwin-help@cygwin.com>, <http://sourceware.org/ml/#faqs>
Sender: cygwin-owner@cygwin.com
Mail-Followup-To: cygwin@cygwin.com
Delivered-To: mailing list cygwin@cygwin.com

Greg, Dave,

A repeat of my activities earlier (file download via IE8 *and* wget) shows =
the problem to have now gone away.

I've still got a copy of the "bad" file - same file size as the "good" setu=
p.exe but with a earlier timestamp:

-rwx------+  1 585728 Aug  5  2008 setup.exe_bad*
-rwx------+  1 585728 Sep 10 11:56 setup.exe*=20

A "file" (OK, not difficult to fool) shows both to be:

MS-DOS executable PE  for MS Windows (GUI) Intel 80386 32-bit, UPX compress=
ed

---

A browser hijack is possible (and something I'll look into), although the f=
act I'm now able to download without problem (via both IE8 and wget) sugges=
ts otherwise. I've not rebooted in the meantime and besides, a download via=
 wget was giving the same problem earlier. This latter observation may be e=
xplained by local proxy caching, though.

The fact that the "bad" setup.exe crashed when executed suggests it might b=
e corrupted in some way. Could some form of proxy issue result in transient=
 data from two independent sources (the genuine setup.exe plus some transie=
nt "ebuddy" traffic) being merged into a single file?

Interestingly, I see multiple WinXP crash dialogs when attmpting to run the=
 "bad" executable. Not something I've seen with other crashing applications=
 before.=20

If either of you guys are sufficiently interested, I can send over a gzip'e=
d copy of the bad file.

Thanks for the interest,

Mike





--
Problem reports:       http://cygwin.com/problems.html
FAQ:                   http://cygwin.com/faq/
Documentation:         http://cygwin.com/docs.html
Unsubscribe info:      http://cygwin.com/ml/#unsubscribe-simple

