bugtraq April 2008 archive
Main Archive Page > Month Archives  > bugtraq archives
bugtraq: heanet.dl.sourceforge.net hacked?

heanet.dl.sourceforge.net hacked?

From: Michael Scheidell <scheidell_at_nospam>
Date: Wed Apr 30 2008 - 15:23:45 GMT
To: bugtraq@securityfocus.com

or have wrong file?

in attempting to upgrade png (due to security problem), we tried to pull from sourceforge mirrors.
(note below, libpng says file size for libpng-1.2.27.tar.bz2 with scripts should be 641193) heanet has a bigger file. other sourceforge.net mirrors have it right.

Was heanet.dl hacked? are some people downloading a trojanized version of png?
all attempts (in the past) to contact sourceforge had been useless.

http://www.libpng.org/pub/png/libpng.html

Attempting to fetch from
http://heanet.dl.sourceforge.net/sourceforge/libpng/. fetch:
http://heanet.dl.sourceforge.net/sourceforge/libpng/libpng-1.2.27.tar.bz2: size mismatch: expected 641193, actual 804821 -- Michael Scheidell, CTO Main: 561-999-5000, Office: 561-939-7259
> *| *SECNAP Network Security Corporation
Winner 2008 Technosium hot company award. www.technosium.com/hotcompanies/ <http://www.technosium.com/hotcompanies/> _____________________________________________________________________________ This email has been scanned and certified safe by SpammerTrap(r). For Information please see http://www.spammertrap.com. _____________________________________________________________________________