7zip.com Is Serving Malware
malwarebytes.com
malwarebytes.com
Search results can be gamed by SEO, there were also cases of malware developers buying ads so links to the malware download show up above legitimate ones. Wikipedia works only for projects prominent enough to have a Wikipedia page.
What are the other mechanisms for finding out the official website of a software?
I dunno, if you type "download 7zip" into Google, the top result is the official website.
Also, 7zip.com is nowhere on the first page, and the most common browsers show you explicitly it's a phishing website.
This is actually a pretty good case of the regular user being pretty safe from downloading malware.
Until someone puts an ad above it.
So the advice is to install it from the extension store.
Are the search removals and phishing warnings reactive or proactive? Because if it is the former then we don't really know how many users are already affected before security researchers got notified and took action.
Also, 7zip is not the only software to be affected by similar domain squatting "attacks." If you search for PuTTY, the unofficial putty.org website will be very high on the list (top place when I googled "download putty.") While it is not serving malware, yet, the fact that the more legitimate sounding domain is not controlled by the original author does leave the door open for future attacks.
In incognito window, for me, it's 3rd result
On google search I don't see it on the first page, and the only sketchy link on page 2 is https://7zip.dev/en/download/.
Bing is worse, since it shows 7zip.com on the 2nd page, but the site refuses to load.
But I am using Thorium with manifest v2 ublock and Edge with medium setting for tracker/ad block.
You don't need to do everything or anything. They're options. Use your own judgment.
2. Go the listed homepage
They could even have support pages that look real, by copying them from the legitimate site.
And the process of creating a repo that stays in sync with another fork can be automated, so, if needed, malware writers likely will do that.
There are risks in everything you do. If the average user doesn't know where the application he wants to download _actually_ comes from then maybe the average user shouldn't use the internet at all?
I think you practically can't and that's the problem.
TLS doesn't help with figuring out which page is the real one, EV certs never really caught on and most financial incentives make such mechanisms unviable. Same for additional sources of information like Wikipedia, since that just shifts the burden of combatting misinformation on the editors there and not every project matters enought to have a page. You could use an OS with a package manager, but not all software is packaged like that and that doesn't immediately make it immune to takeovers or bad actors.
An unreasonable take would be:
> A set of government run repositories and mirrors under a new TLD which is not allowed for anything other than hosting software packages, similar to how .gov ones already owrk - be it through package manager repositories or websites. Only source can be submitted by developers, who also need their ID verified and need to sign every release, it then gets reviewed by the employees and is only published after automated checks as well. Anyone who tries funny business, goes to jail. The unfortunate side effect is that you now live in a dystopia and go to jail anyways.
A more reasonable take would be that it's not something you can solve easily.
> If the average user doesn't know where the application he wants to download _actually_ comes from then maybe the average user shouldn't use the internet at all?
People die in car crashes. We can't eliminate those altogether, but at least we can take steps towards making things better, instead of telling them that maybe they should just not drive. Tough problems regardless.
I agree with the sentiment but there are limits to what we can and should do. To stay with your analogy: We don't let people drive around without taking a test. In that test they have to prove that they know the basics of how to drive a car. At least where I come from that means learning quite a bit of rules and regulations.
In other words: Don't let people off the hook. They need to do some form of learning by themselves. It's no different with what you do on the internet. If you're not willing to do some kind of work to familiarize yourself with how the bloody thing work then it's not the job of everyone else to make sure you'll be okay. It's _your_ job to understand the basics.
I'm getting tired of just another thing we must take off peoples minds so that they can "just" use whatever they want to use. Don't try to blame (or god forbid sue) someone else because you didn't do your homework.
I feel like this line of thinking is dangerous: people hit the wall hard when they don’t have sex ed, or financial education classes, or even basic classes on how to cook or do crafts (we had those in school, girls mostly cooked and the guys got to learn woodworking but also swapped sometimes; and later in university there were classes about work safety in general), or computer literacy classes.
I think a lot of people don’t even have basic mental models of how OSes or the Internet works, what a web browser is (“the Google”) and so on.
Saying that they should know that stuff won’t change the fact that they don’t unless you teach them as a part of their overall education.
In the end that's fine. I have no idea how my car works and if the guy from the repair shop says that I need to pay for a new clutch then that's what I'm gonna do. I am aware that I don't have the knowledge to know whether or not I'm being scammed or not. But I _accept_ that because the alternative (getting to know a lot more details about a car) simply doesn't appeal to me.
If someone wants to use the same approach for everything he does on the internet then that's perfectly fine. But then he needs to accept the consequences as well.
In a post AI world asking how not be scammed is hard cause now everything can be faked.
Trust what you definitely know but still verify.
Especially in the next 5-10 years that's going to become the reality so I guess sit tight and prepare for the waves and sunamis of scams.
Which is enabled by default in uBlock. And installing it is pretty much a standard suggestion for any web user.
Lookalike websites serving malware have always existed. So this isn't exactly news. But the browsers are blocking them like they should.
Like it or not, .com adds perceived trustworthiness and works as a branding signal, especially in these times of VCs throwing large amounts of money at branding and buying 3 to 6 letter .com domains, but a small project like 7zip cannot afford that kind of expense.
An article from 2018:
https://www.bleepingcomputer.com/news/security/fake-websites...
And uBlock Origin's "Badware" filter blocks it:
https://github.com/uBlockOrigin/uAssets/blob/master/filters/...
Did they change it because of the negative publicity (Reddit) and will probably change back soon to the malware links?
But I'm sure people blindly click through the "Unknown author" prompt just as they would ignore a certificate error.
Maybe it's high time for a free-as-in-beer CA for non-profit open source developers funded by donations?
Edit: I was wrong.
Prices on code signing certificates have skyrocketed to in excess of $500/year, due in part to continuing meddling by the CA/B forum which increased the requirements of standard certs to be the same as EV certs, and requiring the key to be stored in a hardware token—which must now be re-issued yearly.
This makes it near impossible to provide free or affordable certificates to developers. Thanks CA/B forum, lots of help as usual.
Note that the certificate itself is only for 1 year regardless of how long you buy one for and you need to go through the renewal process each year just without payment.
Orange when it's missing or invalid.
Whether Authenticode provides a sufficient authenticity check is yet another question, of course. Still, file integrity verification is just a side-effect.
7-zip is not a serious project and its use should be strongly discourged.
Modern Windows and OS X and Android and iOS are all worse than the old ones.
I’m not even joking, they are basically superior in every way. They open faster, they have only one visual axis and they support all the shell extensions you remember. (Too many shell extensions could make them just as slow though.)
I imagine an electron rewrite, with DirectX 12 and Copilot buttons everywhere
How does verification work? Only at installation time or will it prevent running the installed files later if installation happened when the cert was still accepted?
Linux user asking out of curiousity...
[1] https://learn.microsoft.com/en-us/windows/package-manager/pa...
WinGet is not only unreliable, it is but one step removed from Remote Code Execution as a Service. Well, maybe one-and-a-half, if package repo maintainers were to pay attention, but that’s not realistic.