MinGW Notification List
mingw****@lists*****
Wed Aug 22 05:59:17 JST 2018
#38527: www.mingw.org is compromised and serving a trojaned installer Open Date: 2018-08-22 05:59 Last Update: 2018-08-22 05:59 URL for this Ticket: https://osdn.net//projects/mingw/ticket/38527 RSS feed for this Ticket: https://osdn.net/ticket/ticket_rss.php?group_id=3917&tid=38527 --------------------------------------------------------------------- Last Changes/Comment on this Ticket: 2018-08-22 05:59 Updated by: ascendr * New Ticket "www.mingw.org is compromised and serving a trojaned installer" created --------------------------------------------------------------------- Ticket Status: Reporter: ascendr Owner: keith Type: Issues Status: Open [Owner assigned] Priority: 9 - Highest MileStone: (None) Component: INSTALLER Severity: 5 - Medium Resolution: None --------------------------------------------------------------------- Ticket details: www.mingw.org is compromised and is serving a trojaned installer. Trojaned mingw installer is being served from www.mingw.org/sites/www.mingw.org /files/releases/mingw-get-setup.exe The trojan file is 470K instead of the expected 85K The entire /sites child path has Index of (directory traversal) enabled. The trojaned installer seems to install a Banking Trojan. -- Ticket information of MinGW - Minimalist GNU for Windows project MinGW - Minimalist GNU for Windows Project is hosted on OSDN Project URL: https://osdn.net/projects/mingw/ OSDN: https://osdn.net URL for this Ticket: https://osdn.net//projects/mingw/ticket/38527 RSS feed for this Ticket: https://osdn.net/ticket/ticket_rss.php?group_id=3917&tid=38527