Mate you’re the only one whining. I got around the cookie banner just fine, and reposted here for others.
rowdy
- 1 Post
- 58 Comments
rowdy@piefed.socialto
Technology@lemmy.world•Notepad++ updater installed malwareEnglish
119·9 days agowe share data with our 188 partners
That’s a no from me dawg
The updater integrated into Notepad++ has allowed itself to be infiltrated by malware, which has been installed on some PCs. The developer of the powerful open-source text editor is responding with an update to Notepad++ v8.8.9. Users currently have to perform the update manually.
In a news post on the Notepad++ website, developer Don Ho explains that “some security experts have reported incidents where internet traffic affecting Notepad++ was intercepted.” According to the post, investigations have revealed that traffic from the Notepad++ updater WinGUp “was occasionally redirected to malicious servers, leading to the download of compromised executable files.” IT security researcher Kevin Beaumont reports that at least three organizations “with interests in South Asia” have been targeted in this way.
As Beaumont explains, the updater uses a version check that queries the URL “https://notepad-plus-plus.org/update/getDownloadUrl.php” and evaluates an XML file delivered through it. The updater uses the download URL listed in the XML file, saves the file in the %TEMP% folder, and executes it. Anyone who can intercept and manipulate this traffic can therefore change the download URL. Until version 8.8.7 of Notepad++, the developer used a self-signed certificate, which is available in the Github source code. This made it possible to create manipulated updates and push them onto victims. Since v8.8.7, however, Notepad++ relies on a legitimate GlobalSign certificate, and installing its own Notepad++ root certificate is no longer necessary.
Remedy through updates
With Notepad++ v8.8.8, the WinGUp updater now forces github.com as the download source. Version 8.8.9, released overnight on Wednesday, further hardens Notepad++ and WinGUp so that they correctly check the signature and certificates of downloaded installers during the update process. If the check fails, the update process is aborted. Don Ho notes that investigations are ongoing to determine how the traffic hijacking occurred in the observed cases.
Kevin Beaumont also lists some indicators of compromise (IOCs). For example, connections from “gup.exe” to URLs other than “notepad-plus-plus.org”, “github.com”, and “release-assets.githubusercontent.com” are suspicious. Likewise, attention should be paid if “gup.exe” starts unusual processes – only “explorer.exe” and “npp*” related Notepad++ installers should run under it, which since versions 8.8.8 are also signed with a GlobalSign certificate. After the observed attacks, files named “update.exe” or “AutoUpdater.exe” (Notepad++ itself does not use these names at all) were apparently also found in the user’s TEMP directory, from which “gup.exe” downloaded and executed the updaters.
Notepad++ v8.8.8 currently does not find the update.
Beaumont recommends updating to at least Notepad++ v8.8.8. However, version 8.8.9 is even further hardened. The integrated updater from Notepad++ v8.8.8 does not yet find the update, and “winget” also does not currently find a newer software version. However, the latest version is available as a manual download on the Notepad++ website.
Notepad++ is frequently targeted by malicious actors because the software is popular and widely used. Last year, for example, Don Ho asked for help to get rid of a “parasitic website” that was creeping into the original Notepad++ site in Google search results. It had unscrupulous intentions. In general, fake sites often appear in search results offering virus-infected files.
(dmk)
This article was originally published inGerman. It was translated with technical assistance and editorially reviewed before publication.
rowdy@piefed.socialto
Steam Hardware@sopuli.xyz•Valve has plans for a travel case that charges your Steam Deck, leak revealsEnglish
4·21 days agoCitation needed - but I suppose you could say the same about my claim.
I’d love to test this properly with an infrared thermometer but I don’t have one. All I have is an anecdote that I’ve been charging my OLED in it’s case since release and have never had an issue - not zipped up given the wire, just the lid flipped over on top.
I guess either way the BMS would prevent any real damage from occurring, which is why I say it’s a non-issue.
rowdy@piefed.socialto
Steam Hardware@sopuli.xyz•Valve has plans for a travel case that charges your Steam Deck, leak revealsEnglish
191·22 days agoI can understand the concern. But a SD at full load would run significantly hotter, even with fan exhaust, than a powered-off SD charging in an enclosed case. It’s a non-issue.
rowdy@piefed.socialto
Ask Lemmy@lemmy.world•What's an unscientific opinion that you firmly hold?English
41·24 days agoopens thread for stupid opinions
reads stupid opinion
gets upset an opinion is stupidYou.
Most literate people have never written a book. Blind and deaf people are not a monolith, doubting one does not automatically apply to all like you’re implying. If you’re going to criticize me, at least quote me correctly you goober. Go be needlessly upset somewhere else.
rowdy@piefed.socialto
Ask Lemmy@lemmy.world•What's an unscientific opinion that you firmly hold?English
53·24 days agoMate. Look at where you’re at. People aren’t upvoting me because I’m right, they’re upvoting me because I answered the question.
there’s no way a deaf and blind person could have been literate
Keep your words out of my mouth. You’re just looking for an excuse to be offended.
rowdy@piefed.socialto
Ask Lemmy@lemmy.world•What's an unscientific opinion that you firmly hold?English
399·25 days agoI got one - and it’s the only conspiracy theory I give any credence to.
All of Helen Keller’s feats were utter bullshit and were a circus side show to bring money to her family. It’s the perfect “you can do anything if you just put your mind to it” fairytale. Like hell she flew an airplane, ain’t no way she wrote a book.
Before anyone provides evidence of the contrary, I will not accept it no matter how damning it is. Hence the “firmly hold.”
rowdy@piefed.socialto
Unpopular Opinion@lemmy.world•‘R-tarded’ is a slur, and I’m sick of otherwise “liberal” people going along with the right’s move to renormalize itEnglish
459·25 days agoHonestly, it’s not a word in my vocabulary but I think this opinion is moronic, idiotic even.
The only reason it continues to be offense to those living with mental disabilities is because there are people like yourself who keep attributing the word to them.
rowdy@piefed.socialto
Shirts That Go Hard@lemmy.world•From a conversation with a neighborhood friend. :)English
50·27 days agoMajority of the shirts in this community are just “shirts that may mildly amuse you”
rowdy@piefed.socialto
B Movie Bonanza@lemmy.world•Alligator (1980) - Mastodon watch party this Sunday evening!English
9·1 month agoI love the art for this poster.
Just to nitpick, a 36ft alligator at 2000lbs would be a frail stick of an alligator. Theoretically, an alligator of that size would be closer to 8000lbs.
rowdy@piefed.socialto
World News@lemmy.world•Why Americans trying to hide as Canadians overseas doesn’t workEnglish
93·2 months agoI’ve been overseas a lot this year, and if anyone asks where I’m from my go-to response is “I’m American but I’m telling people Canadian.”
It’s a cheeky joke, without actually needing to lie about where I’m from, and is a clear indication that I don’t agree with the batshit crazy that’s going on in my country.
Yes. I’ve used this site before but I can’t guarantee how safe it is:
rowdy@piefed.socialto
science@lemmy.world•Rats filmed snatching bats from air for first timeEnglish
4·2 months agoAn invasive rat using a man-made platform in a natural cave to decimate bat population and create a vector for disease.
It would’ve been nice if any of the humans in the article had offered potential solutions to fixing this problem we created.
Edit: I didn’t see the scientific paper linked at the bottom. Added to my reading list, hopefully there are some solutions there.
Edit 2: They’ve got some ideas:
Furthermore, straightforward infrastructure modifications can restrict rat access to bat hibernacula. For example, removing the black fabric that acted as a climbing aid at the Segeberg Kalkberg entrance eliminated predation around the light-barrier system. Additional measures – such as sealing foundation joints, blocking connections from caves to sewers and modernizing drainage systems - can prevent dispersal via sewers (Adrichem van et al., 2013). Active control should then be guided by a quantitative baseline of rat abundance: capture-mark-recapture grids, camera trap encounter rates or chew-card bite indices can clarify whether predation is driven by a few transient individuals or by a resident colony (Cavia et al., 2012, Nottingham et al., 2021, Mackenzie et al., 2022). Mechanical traps and, where legally permissible, strictly regulated rodenticides remain core tools, while integrated programs in Amsterdam and Rotterdam show that coupling waste management, public outreach, habitat modification and ongoing sewer maintenance can be highly effective (Adrichem van et al., 2013, Cock et al., 2024) Together, these measures can limit invasive-rat predation at urban hibernacula, reinforce bat-conservation objectives and reduce potential public health risks within a One-Health framework.
Poor guy asked for an .ipa file he can use with SideStore and still got linked to an .apk
Here, you’ll need to build it yourself or find an .ipa floating around: https://github.com/whoeevee/EeveeSpotifyReborn
If you trust me, a random stranger on the internet, I can send you the .ipa I have. But you’d be better off building it yourself.
Easy. D.
A. might have been a good answer but always remember to pay attention to the question’s phrasing.
Your childhood dog was the best boy. Current dog is the best boy.
Holy shit, are you comparing potential property damage to literal murder? Your brain rot is showing.
Edit: To add to this, when I’m impeded by a “jaywalker” I might think “bruh” or “where’s the hustle?”. Not once in my entire life have I thought “I should just run you down.” You may be an actual psychopath.
rowdy@piefed.socialto
General Memes & Private Chuckle@lemmy.dbzer0.com•Oscar nominatedEnglish
6·2 months agoI’ve seen it. It rocks. Definitely recommend with friends and drinks, if that’s your prerogative.
[VFX: Car on fire]
This guy gets it!
It sure would be nice to know the name of the human behind all of the animal art - it’s quite nice. I’m sure I speak for most of us here when I say I could not care less about crediting a random company.







This might work for you: https://github.com/aonez/Keka