• We’re currently investigating an issue related to the forum theme and styling that is impacting page layout and visual formatting. The problem has been identified, and we are actively working on a resolution. There is no impact to user data or functionality, this is strictly a front-end display issue. We’ll post an update once the fix has been deployed. Thanks for your patience while we get this sorted.

Can sourceforge be trusted now?

Even if it is, simply prescan by url with virustotal and if necessary (i.e. malware is indeed bundled and it is not available elsewhere) then extract or install in a sandbox and recover the contents.
 
I know SF is up for sale again, and they did have a download wrapper on some projects.\, though, last I heard, they stopped doing that.

So, you can still get stuff from them, but always check the hash of the files to make sure they are originals, assuming those are posted someplace.
Usually, you need to fire off a e-mail on their ML, and they will tell you the hashes.
 
I know SF is up for sale again, and they did have a download wrapper on some projects.\, though, last I heard, they stopped doing that.

So, you can still get stuff from them, but always check the hash of the files to make sure they are originals, assuming those are posted someplace.
Usually, you need to fire off a e-mail on their ML, and they will tell you the hashes.
Once a murders, always a murder.
 

Oh so I should be safe if I just grab the installer from there? I'll try that then. Since this is a compiler it's kinda critical it has no spyware as nothing stops them from modifying it to inject spyware in anything I compile for example. I've always just used Dev-C++ in Windows which comes with gcc but I should probably use something newer.
 
I say you would be safer than grabbing it from the main page. That seems to bypass the "sourceforge installer" they mentioned in the article. I would also upload the file to virustotal like Auric mentioned.

Edit: Here are the VT results from your download link. https://www.virustotal.com/en/file/...86e8f0032b49dd0410f232bc/analysis/1453508744/

I never heard of the two programs that show a detection. I would take them with a grain of salt.
 
Last edited:
Back
Top