New on LowEndTalk? Please Register and read our Community Rules.
All new Registrations are manually reviewed and approved, so a short delay after registration may occur before your account becomes active.
All new Registrations are manually reviewed and approved, so a short delay after registration may occur before your account becomes active.
Xubuntu website got hacked and is serving malware (trojan)
in News
Just be aware, Xubuntu.org got hacked and their download button tries to download “Xubuntu-Safe-Download.zip”, that seems to include a fake TOS and an EXE, and Virustotal confirms malware (a Trojan) inside of it. Seems someone’s trying to get noobs from Windows that could be interested in Linux (more so now because the Win10 EOL)
https://www.reddit.com/r/linux/comments/1oad1m6/xubuntu_website_got_hacked_and_is_serving_malware/

Comments
Damn, that's really bad.
404 on my side, file seems to have been removed.
If anyone has the zip please PM me, I couldn't get it in my sandbox in time.
I think that the file was removed a while ago -- it's the web page + links that they haven't yet changed
Seems you are correct. Surprised more AV vendors hadn't flagged it yet then.
I have this conspiracy theory where actual 2-3 AVs do the job and rest just wait for signature/behavior pattern to be published by those AVs through some group chat.
xubuntu.org keeps getting hacked since it runs an outdated wordpress version by canonical. I keep complaining every few months on their IRC channel, they revert it and it gets hacked again few days later.
if you want safe download links use https://cdimage.ubuntu.com/xubuntu/releases/ It is hosted on a different container apparently.
Nice try, Fedora.
The fact that they can't do the basics to manage their website makes me sceptical of the entire Distro. Red flags being red flags and all of that...
Duh, businesses, run their Wordpress instances like this.
Seems kinda normal for some.
super annoying, would be nice if there was no hacking.
They won’t even update WordPress after being attacked so many times?
Hacked by black red hats
Yesterday I wrote on the Canonical portal to alert the community, but their reaction was to obscure the issue.
https://discourse.ubuntu.com/t/xubuntu-org-hacked/70074
Its not just this distro
All are hijacked daily.
Even ms .iso
And yet 99% even of even cyber security guys wont see their run compromised crao