Re: [Full-disclosure] RE: Download Accelerator Plus can be tricked to download malicious file

2006-01-05 Thread Bipin Gautam
>All mirrors from DAP were in speedbit server, and were validated as >Application Servers like (twcows, downloads.com, etc) so there's no >matter about corrupted or backdoored file as I see. ok agreed. but sorry for my ignorance but who are responsible to keep track of the integrity of al

[Full-disclosure] RE: Download Accelerator Plus can be tricked to download malicious file

2006-01-05 Thread NaPa
Here Is The investigation about DAP, as I see there's no problem and no flaw at this time, but someone can act as a Proxy and replace some text mirrors form the list that Mirrorssearch.speedbit.com response. On this way could a user download some malicious file without knowledge. Affected: Every

[Full-disclosure] Re: Download Accelerator Plus can be tricked to download malicious file

2006-01-05 Thread Bipin Gautam
Just n' update: DAP searches for all its mirrors from mirrorsearch.speedbit.com I have no knowledge about HOW the mirrors are gathered. Still waiting for DAP developers to comment on this. regards, -Bipin Gautam http://bipin.tk On 1/4/06, Bipin Gautam <[EMAIL PROTECTED]> wrote: > Product(ONLY T