Community

    • Login
    • Search
    • Recent
    • Tags
    • Popular
    • Users
    • Groups
    • Search
    1. Home
    2. Security
    Log in to post
    • Newest to Oldest
    • Oldest to Newest
    • Most Posts
    • Most Votes
    • Most Views
    • ?

      Why can't I sign up with a Notepad++ Forum Account?
      • A Former User

      4
      0
      Votes
      4
      Posts
      93
      Views

      PeterJones

      The original user appears to have deleted their account.

      Had they stayed, my response would have been that privacy is addressed in the FAQ. And as mentioned there, it is simple enough to sign up for an account with one or more of the OAUTH providers that gives the OAUTH provider no private information, so that the OAUTH provider cannot provide this Community Forum with any private information.

      For future readers: changing the password does nothing, because there is no username/password login available. (The forum software will not allow us to hide that setting)

    • timint01

      Community Digest fails SPF, DKIM DMARC
      • timint01

      1
      0
      Votes
      1
      Posts
      196
      Views

      No one has replied

    • UraniumCookie

      Notepad++ - Fake website ?
      • UraniumCookie

      2
      2
      Votes
      2
      Posts
      388
      Views

      PeterJones

      @uraniumcookie ,

      That is an impersonation/spoof site. Do not trust downloads of Notepad++ from anyplace but notepad-plus-plus.org or github.com/notepad-plus-plus/notepad-plus-plus

    • jonathandl2

      Compare plugin detected as malicious by both JoeSandbox and Crowdstrike Falcon
      • jonathandl2

      5
      0
      Votes
      5
      Posts
      530
      Views

      jonathandl2

      @rdipardo said in Compare plugin detected as malicious by both JoeSandbox and Crowdstrike Falcon:

      …it unpacks portable versins of sqlite3 and git2, which it needs to function; but these are flagged as potentially malicious “stowaways”:

      Persistence and Installation Behavior

      Drops PE files

      Source: C:\Windows\SysWOW64\7za.exe
      File created: C:\Users\user\Desktop\extract\ComparePlugin\sqlite3.dll

      Source: C:\Windows\SysWOW64\7za.exe
      File created: C:\Users\user\Desktop\extract\ComparePlugin\git2.dll

      Source: C:\Windows\SysWOW64\7za.exe
      File created: C:\Users\user\Desktop\extract\ComparePlugin.dll

      Yes. It appears the sqlite3.dll and git2.dll files are the ones actually causing the Hybrid-Analysis sandbox to register the whole .zip as malicious as well. Not sure the best way to test them to verify they are good…

    • Serge Adourian

      notepad.exe keeps running in Task Manager
      • Serge Adourian

      4
      0
      Votes
      4
      Posts
      325
      Views

      ?

      @serge-adourian Don’t download NPP from an unofficial site

    • Digital Streaming

      VirusTotal.Com Analysis of npp.8.1.9.2.Installer.x64.exe Reports "Detects executables signed with stolen, revoked or invalid certificates"
      • Digital Streaming

      11
      0
      Votes
      11
      Posts
      884
      Views

      Digital Streaming

      @imspecial said in VirusTotal.Com Analysis of npp.8.1.9.2.Installer.x64.exe Reports "Detects executables signed with stolen, revoked or invalid certificates":

      Maybe this has something to do with this?

      https://www.bleepingcomputer.com/news/security/malicious-notepad-plus-plus-installers-push-strongpity-malware/

      If that is the case, then that is on the user for not downloading it from official/reputable places and has nothing to do with Notepad++ really, as it has no control on where the user get these files from.

      Actually I was just addressing what I quoted above. I thought it would be a good idea to get your feedback on the file’s hash and the location of the download which I included in the original post.

      Thx

    • Hart BrownYT

      Log4j Vulnerability
      • Hart BrownYT

      4
      0
      Votes
      4
      Posts
      3981
      Views

      Hart BrownYT

      @peterjones Thanks!

    • pjamesburwell

      Where did always open in Administrator Mode go in the later Notepad++ Context Menu?
      • pjamesburwell

      2
      0
      Votes
      2
      Posts
      218
      Views

      PeterJones

      @pjamesburwell ,

      Sorry, I don’t recall in my decade or more of using Notepad++ ever seeing an always-open-in-administrator-mode right-click option.

      If you want that to always be the case, you might be able to use Windows OS techniques to accomplish it: right click on the Notepad++.exe executable, and go to the Compatibility tab, and select the appropriate checkbox on that tab. I think that will make it so Notepad++ will always open in Admin mode, even called from a shortcut or a right-click context “open file”/“open file with” action. But Admin mode is controlled by the OS, not by the application, so the final word has to come from the OS.

    • vmars vernon

      How to NOT show STX code on text page ?
      contro characte stx • • vmars vernon

      4
      0
      Votes
      4
      Posts
      799
      Views

      vmars vernon

      @PeterJones
      or by using the newer way (which is so much easier) of just having the image in your copy buffer and pasting it in your reply, which will host the image on our server, so IT departments will be less likely to block it – and that way it would still be a valid image

      264174d9-dacd-4da7-9f4e-39cac0b30413-image.png

      Thanks Peter

    • Michael L.E.

      Checksums
      • Michael L.E.

      2
      0
      Votes
      2
      Posts
      205
      Views

      Terry R

      @Michael-L-E said in Checksums:

      Can anybody tell me why the SHA1, SHA256, and MD5 checksums aren’t available to compare with the downloads?

      There does appear to be SHA256 info available for the 8.1.3 version. Look here, about half way down the site’s page. Titled Integrity & Authenticity validation.

      Terry

    • Mike Geubel

      Prevent access to local drives or command prompt
      • Mike Geubel

      2
      0
      Votes
      2
      Posts
      136
      Views

      Alan Kilborn

      @Mike-Geubel

      Not 100% sure of what you’re asking, but it sounds like you want Notepad++ to be the shepherd of access to other things on the PC it is installed upon?

      If so, it is not reasonable. That’s the operating system’s job. You should look into setting that up via the OS.

    • Jnoel111

      Need someone to validate 2 files from notepad ++ updater
      • Jnoel111

      2
      0
      Votes
      2
      Posts
      134
      Views

      PeterJones

      @Jnoel111 ,

      Last-modified dates can be changed for reasons that don’t seem like the file being “modified” to mere mortals.

      I found no documentation on this change

      The executables and DLLs that ship with Notepad++ (including the updater and the plugin list) generally get updated with every release.

      v7.8.7 was released June 8, 2020 . The zipfile version of the v7.8.7 downloads shows dates of 6/4/2020 for those files. But, like I said, the install process itself, or otherwise touching the files even if they weren’t modified, may have changed the dates.

      If you’re worried that your files have been changed from the official distribution, you could download the zipfile version (make sure to grab the correct 32bit or 64bit, depending on your current installation) from the official download page, and do a comparison of the “modified” files vs the files in the zipfile – or just overwrite the files in your installation with the files from the zipfile to be sure.

      Or just grab the most recent v7.9.5 download and install the newest version to get the most recent enhancements and bug fixes.

    • Aleksandr Baghramyan

      VirusTotal Detects a Malware in the Official npp.7.9.5.Installer.x64.exe
      • Aleksandr Baghramyan

      9
      4
      Votes
      9
      Posts
      610
      Views

      PeterJones

      I just told https://www.virustotal.com/gui/file/4881548cd86491b453520e83c19292c93b9c6ce485a1f9eb9301e3913a9baced/detection to re-scan, and this time it came up clean, but the Zillya scanner is no longer listed… so presumably sites that still use the zillya scanner will continue to get false positives.

      @b00kgrrl , I don’t know if it’s possible to update your Windows Security / Windows Defender / whatever’s doing the scan, but maybe you could scan the installer again, and see if you can make it work without triggering Windows Security alert.

    • TomyLobo

      !!! Release key expires tomorrow !!!
      • TomyLobo

      4
      0
      Votes
      4
      Posts
      162
      Views

      TomyLobo

      Thanks for the info. That explains why the code signing cert date does not align with the gpg key date. I guess I’ll remove all the exclamation marks since it doesn’t seem that urgent… or I would, if I could.

    • ?

      This topic is deleted!
      • A Former User

      1
      0
      Votes
      1
      Posts
      1
      Views

      No one has replied

    • Alex Connor

      This topic is deleted!
      • Alex Connor

      1
      -7
      Votes
      1
      Posts
      14
      Views

      No one has replied

    • E R

      Virus Total False Positive
      • E R

      7
      0
      Votes
      7
      Posts
      7672
      Views

      rituros limura

      Vpn can help to protect online privacy during web surfing. I have experience with using VeePN VPN during remote working and unblocking new websites without problems.

    • Szelzz

      Wrong cert on download pages
      • Szelzz

      4
      2
      Votes
      4
      Posts
      510
      Views

      Ekopalypse

      @oneday-oneyear

      ?? - What are you trying to tell us ??

    • twgiu

      Trojan:Trojan.GenericKD.3016333 - Ransomware
      • twgiu

      2
      0
      Votes
      2
      Posts
      199
      Views

      L

      Hi @twgiu I just downloaded the 32-bit version of Notepad++ from the official website (https://notepad-plus-plus.org/downloads/v7.9.1/) and sent notepad++.exe to virustotal. One of the 72 engines detected malware (Trojan.Generic.giteg). I also uploaded the 64-bit version and it was clean.
      Being only one engine, named Jiangmin, that detected the virus I’d would be inclined to say that it is a false positive. If possible you can test the 64-bit version and if it results clean, then use that version?

      For peace of mind you can also post an issue in github (https://github.com/notepad-plus-plus/notepad-plus-plus) where notepad++ developers could confirm whether the downloads are legit or not.

    • ?

      user manual outdated.
      • A Former User

      3
      0
      Votes
      3
      Posts
      99
      Views

      L

      @A-Former-User said in user manual outdated.:

      it also doesn’t work when I click proceed to npp-user-manual.org(unsafe)

      I could open that link without problems in Google Chrome, it seems the certificate is valid since October. However, www.npp-user-manual.org was giving the same warning you saw… I cleared my browsing data, including ‘Passwords and other sign-in data’, restarted the browser and now it working proeprly. It happened the same with Firefox and I ‘fixed’ the issue by clearing all my browsing data and restarting…
      I guess there must be some place in the network and/or in our browsers that is keeping our local certificates from updating?

    Copyright © 2014 NodeBB Forums | Contributors