My question was in relation to a unsigned executable on an unencrypted http site, as the OP site loads by default. Would you download and run one?
My question was in relation to a unsigned executable on an unencrypted http site, as the OP site loads by default. Would you download and run one?
The same is probably equivalently applicable to the hardware that was used to compile the compiler that compiled the compiler that compiled the compiler that you're using.
Therefore, an unsigned binary is an unsigned binary, no matter the transport mechanism. I agree that distributing unsigned binaries is poor security practice, but I also think that it is dangerous to think that the transport of an unsigned binary over an SSL connection gives it any credibility.
Once implemented, it's much easier than hacking servers and more convenient to do targeted, semi-targeted, local network/cafe script-kiddie attacks, without it being easily detected. Unfortunately for attackers, these days people don't download and run unverified executables as often, especially over http, so you may need lots of patience if you want do infect a specific person.
MITM executable patching attacks are not theoretical. AFAIU, the first hit on "mitm executable infection" [1] and an interceptor (ARP/wifi/whatever) is all a script kiddie needs.
I got: http://www.spectrum-soft.com/download/mc12cd.zip sha3-256: 1e9c7d1ec04019446fa448fec74af36f53eaf6508def75068eb32ae0d7f5109a
https://www.virustotal.com/gui/file/773a060c5c824f6c47352dea...