Can sourceforge be trusted now?

Auric

Diamond Member
Oct 11, 1999
9,591
2
71
Even if it is, simply prescan by url with virustotal and if necessary (i.e. malware is indeed bundled and it is not available elsewhere) then extract or install in a sandbox and recover the contents.
 

lxskllr

No Lifer
Nov 30, 2004
59,089
9,505
126
No, I don't trust them, but it's the home page for some projects, so they have to be dealt with.
 

Elixer

Lifer
May 7, 2002
10,371
762
126
I know SF is up for sale again, and they did have a download wrapper on some projects.\, though, last I heard, they stopped doing that.

So, you can still get stuff from them, but always check the hash of the files to make sure they are originals, assuming those are posted someplace.
Usually, you need to fire off a e-mail on their ML, and they will tell you the hashes.
 

BarkingGhostar

Diamond Member
Nov 20, 2009
8,410
1,617
136
I know SF is up for sale again, and they did have a download wrapper on some projects.\, though, last I heard, they stopped doing that.

So, you can still get stuff from them, but always check the hash of the files to make sure they are originals, assuming those are posted someplace.
Usually, you need to fire off a e-mail on their ML, and they will tell you the hashes.
Once a murders, always a murder.
 

Red Squirrel

No Lifer
May 24, 2003
69,723
13,342
126
www.betteroff.ca

Oh so I should be safe if I just grab the installer from there? I'll try that then. Since this is a compiler it's kinda critical it has no spyware as nothing stops them from modifying it to inject spyware in anything I compile for example. I've always just used Dev-C++ in Windows which comes with gcc but I should probably use something newer.
 

balloonshark

Diamond Member
Jun 5, 2008
6,894
3,366
136
I say you would be safer than grabbing it from the main page. That seems to bypass the "sourceforge installer" they mentioned in the article. I would also upload the file to virustotal like Auric mentioned.

Edit: Here are the VT results from your download link. https://www.virustotal.com/en/file/...86e8f0032b49dd0410f232bc/analysis/1453508744/

I never heard of the two programs that show a detection. I would take them with a grain of salt.
 
Last edited: