This forum has been archived. All content is frozen. Please use KDE Discuss instead.
The Discussions and Opinions forum is a place for open discussion regarding everything related to KDE, within the boundaries of KDE Code of Conduct. If you have a question or need a solution for a KDE problem, please post in the apppropriate forum instead.

Malware @ kde-look.org

Tags: None
(comma "," separated)
ByteEnable
Registered Member
Posts
3
Karma
0
OS

Malware @ kde-look.org

Tue Aug 04, 2009 11:24 pm
I downloaded with the Windows 7 plasma theme for KDE4 from kde-look.org. After activating it, it spawned a flash applet that loaded a bunch of ads and prevented me from using my computer. I had to log out of KDE4.

Nice.

Byte
User avatar
bcooksley
Administrator
Posts
19765
Karma
87
OS

Re: Malware @ kde-look.org

Wed Aug 05, 2009 4:34 am
Please report this to the kde-look.org Administrators ( by convention, likely webmaster@kde-look.org ) so it can be removed.


KDE Sysadmin
[img]content/bcooksley_sig.png[/img]
User avatar
Dante Ashton
Registered Member
Posts
525
Karma
3
OS

Re: Malware @ kde-look.org

Thu Aug 06, 2009 2:55 pm
How lovely.

Can I ask why we don't have security protocols active for knewstuff? Seems silly not to, as this case proves.


Dante Ashton, in the KDE Community since 2008-Nov.
-Artificial Intelligence Specialist.
User avatar
bcooksley
Administrator
Posts
19765
Karma
87
OS

Re: Malware @ kde-look.org

Fri Aug 07, 2009 8:03 am
Unfortunately, such a thing isn't possible, although a "Bad Download" or so button on GetHotNewStuff probably could help, with it bringing that download to the attention of the administrators.


KDE Sysadmin
[img]content/bcooksley_sig.png[/img]
User avatar
Dante Ashton
Registered Member
Posts
525
Karma
3
OS

Re: Malware @ kde-look.org

Sat Aug 08, 2009 12:00 pm
Damn.


Dante Ashton, in the KDE Community since 2008-Nov.
-Artificial Intelligence Specialist.
ByteEnable
Registered Member
Posts
3
Karma
0
OS

Re: Malware @ kde-look.org

Sun Aug 09, 2009 5:49 am
I cannot figure out how the theme launched the flash applet after examining the downloaded files more closely. I was on kde-look.org with konqueror at the same time I downloaded the theme. Maybe it was some sort of web exploit that was on kde-look.org.

Bye
User avatar
Dante Ashton
Registered Member
Posts
525
Karma
3
OS

Re: Malware @ kde-look.org

Sun Aug 09, 2009 8:41 pm
Well, it would make sense to target a KDE-centric site with malware to exploit Konq. As far as I know, despite Kong not being able to handle the more modern techniques, it is still as vulrenble to them.


Dante Ashton, in the KDE Community since 2008-Nov.
-Artificial Intelligence Specialist.
User avatar
bcooksley
Administrator
Posts
19765
Karma
87
OS

Re: Malware @ kde-look.org

Mon Aug 10, 2009 4:58 am
@ByteEnable: can you please provide a link to the applet in question?


KDE Sysadmin
[img]content/bcooksley_sig.png[/img]
User avatar
Madman
Registered Member
Posts
593
Karma
1
OS

Re: Malware @ kde-look.org

Tue Aug 18, 2009 8:14 pm
I don't understand this... A theme is just a tarball with SVG files in it, isn't it? And I just tried downloading a theme called, "Windows 7" which had a rating of 29 (nice). Nothing happened. It was just a duplicate of the Oxygen theme. I tried setting it as my theme, still nothing happened.

Very odd...


Madman, proud to be a member of KDE forums since 2008-Oct.
User avatar
bcooksley
Administrator
Posts
19765
Karma
87
OS

Re: Malware @ kde-look.org

Tue Aug 18, 2009 8:20 pm
Correct, a theme is simply a collection of SVG files.


KDE Sysadmin
[img]content/bcooksley_sig.png[/img]
User avatar
Madman
Registered Member
Posts
593
Karma
1
OS

Re: Malware @ kde-look.org

Tue Aug 18, 2009 8:23 pm
If Konqueror was open at the same time, then what were you doing with it? Can you link this definitely against the content on kde-look?


Madman, proud to be a member of KDE forums since 2008-Oct.


Bookmarks



Who is online

Registered users: abc72656, Bing [Bot], daret, Google [Bot], Sogou [Bot], Yahoo [Bot]