this post was submitted on 09 Apr 2024
170 points (99.4% liked)

Notepad++

182 readers
1 users here now

A community for discussing the notepad++ text editor https://notepad-plus-plus.org/

Looking for mods, if you want to mod the community feel free to dm @[email protected]

founded 5 months ago
MODERATORS
 

The Notepad++ project is seeking the public's help in taking down a copycat website that closely impersonates Notepad++ but is not affiliated with the project. There is some concern that it could pose security threats—for example, if it starts pushing malicious releases or spam someday either deliberately or as a result of a hijack.

top 14 comments
sorted by: hot top controversial new old
[–] [email protected] 121 points 3 months ago* (last edited 1 month ago)

I actually work for the registry that is site is registered with. Identity Digital has an abuse policy in place, so if any evidence of malware distribution or anything that runs afoul of said policy pops up I can escalate the handling of this site internally. I’ll check back on this and similar articles and forums to see if any update happens, but PMing me here on Lemmy also works too. However, until they do something that goes against one of our policies, my hands are tied unfortunately.

Edit: I can refer this to legal and see where the trademark dispute falls.

Edit 2, 2024.05.22: I’ve sent two emails to the developer’s email address, no response received.

[–] [email protected] 20 points 3 months ago (1 children)

Oh, this is something that didn't occur to me before, but I actually create similar look-alike websites (that are usually just a proxy-pass) for a few tools or libraries pretty often. I'm using them at work during pentesting engagement to legitimize our c2 api calls. (So for example you have c2 as a notepad++ DLL calling to api.notepadplus.plus or something like that, which is our c2, and the notepadplus.plus is just a proxypass for the real page.)

I never realized that a search engine may actually pick it up during the time it's up, and that the post may have very well be about something I made.

[–] thesystemisdown 4 points 3 months ago* (last edited 3 months ago)

The website in question does contain a clear disclaimer at the bottom spelling out that it's "an unofficial fan website" and "not affiliated" with the project.

I hear ya though. I usually filter by IP for dev sites for the same reason. It's not 100%, but it keeps them from getting indexed. I don't think there's anything interesting enough to make an effort worthwhile in my case anyway.

[–] [email protected] 17 points 3 months ago* (last edited 2 months ago) (2 children)

Reporting the website for malicious content when its a glorified redirect seems a bit harsh tbh. Why not try to set up a dialogue with the copycat website owner first before burning bridges?

[–] [email protected] 16 points 2 months ago

In this situation, I wish Google offered a “Not Authoritative” option to report sites.

But I mean, doing so would mean then that users have the opportunity to improve google’s search algorithm so that it’s useful, and therefore folks spend less time hunting for info on sites that serve Google Ads. So… that won’t happen.

[–] [email protected] 6 points 2 months ago (1 children)

So should we wait until they do, users download it and only then should we start appeals to have it taken down?

[–] [email protected] 1 points 2 months ago* (last edited 2 months ago) (1 children)

I specifically said set up a dialogue FIRST. Sure if the owner does not respond or acts in bad faith, they can escalate.

Immediately starting with reporting the copycat as malicious seems like a overreaction.

[–] [email protected] 1 points 2 months ago

I don't think so. This absolutely looks to me similar as the xz problem that's hot right now. They set up a website that looks nicer and more polished than the original one, they link the original website at first, the little bitty disclaimer at the bottom is there just for the plausible deniability... Then, when enough people trust it (and Google's algorithm maybe starts showing it first, who knows...) they can just change the links and suddenly there's an attack.

Maybe if the site had a big "fan site" text in the header where everyone can see it right away, I would be less suspicious.

[–] Omgarm 3 points 3 months ago

Well the url is pretty good, I can see why people fall for it.

[–] slazer2au 3 points 3 months ago (1 children)

Doesn't ICANN have a takedown method specifically for these kind of situations?

[–] [email protected] 2 points 2 months ago

Probably, but I Don't think people want to escalate it to ICANN without even asking the person first and going to the domain registrar

[–] [email protected] 2 points 2 months ago* (last edited 2 months ago) (2 children)

The source: Notepad++ news: Help us to take down the parasite website


Looks like that website is already down. I certainly can't reach it. Or is that my adguard DNS blocking known ad- or malware?

[–] [email protected] 1 points 2 months ago

I did my part!

[–] [email protected] 1 points 2 months ago

It's still up for me.