One of those two sites is distributing adware. Which of them?

File Converter (FOSS) by Adrien Allard was hosted on file-converter[.]org since a decade. Then someone a few weeks ago snatched that domain and it’s now distributing adware. Almost identical design for the page, 100% designed to deceive users to download a different product, as it’s called Zamzar.

  • Moonrise2473@feddit.itOP
    link
    fedilink
    English
    arrow-up
    2
    ·
    1 month ago

    In the github issues the dev is aware of this but he’s not completely enraged, just mildly infuriated that the design is too similar and he’s politely asking to have a different design.

    From the history in the wayback machine i don’t see any “parking” page between the switch, so my guesswork is that the dev has been approached with an offer like “we like that domain, we would like to buy it for $$$”, unaware that they would copy the design like that in order to achieve maximum deception of users

  • jet@hackertalks.com
    link
    fedilink
    English
    arrow-up
    1
    ·
    1 month ago

    The benefit of using a package manager like Winget, brew, apt, snap, fdroid is that these attacks are less likely especially with doubly signed reproducible builds like fdroid

  • OsrsNeedsF2P@lemmy.ml
    link
    fedilink
    English
    arrow-up
    2
    arrow-down
    1
    ·
    1 month ago

    If you contact the .org registry they’ll take it down. .org is for non-profits

  • DudeDudenson@lemmings.world
    link
    fedilink
    English
    arrow-up
    1
    ·
    edit-2
    1 month ago

    The domain for my country is .ar and most sites that use said domain use .com.ar

    Someone registered com under the .com.ar domain so if you add .com.ar to any url that ends in .com you get redirected to their adware site

  • irotsoma@lemmy.world
    link
    fedilink
    English
    arrow-up
    0
    ·
    1 month ago

    It seems it’s not so much they stole the domain, it’s that they are using the same name with a different top-level domain. This is a common shady practice in malware. Most people can’t afford to purchase every TLD or their domain and so just pick one or two. Problem is that search engines will find the bad TLDs and suggest them over the real TLD if the malware providers do proper SEO manipulation. A FOSS author is unlikely to be able to or afford the time and effort it takes to manipulate search results and most popular search engines are not doing much to fix the problem, and instead relying on “AI” to reduce the costs of maintaining their search results, which does a pretty bad job, IMHO.

    • Moonrise2473@feddit.itOP
      link
      fedilink
      English
      arrow-up
      1
      ·
      1 month ago

      originally it was hosted in the .org domain, then somehow it changed hands and it was changed to .io

      • irotsoma@lemmy.world
        link
        fedilink
        English
        arrow-up
        1
        ·
        1 month ago

        Ah, thanks for clarifying. I didn’t see that mentioned anywhere and the git repo is showing .io