#9425 google/mozilla 'safe browsing' misdetecting f33 downloads as malware
Closed: Fixed by kevin. Opened by linuxchris.

Describe what you would like us to do:


I found that the mirror:
http://laotzu.ftp.acc.umu.se/mirror/fedora/linux/releases/33/Workstation/x86_64/iso/Fedora-Workstation-Live-x86_64-33-1.2.iso
distributes a compromized version of Fedora 33. At least that is indicated by the firefox
malware detection. Please check and remove the mirror ASAP

EDIT: the file seems to be fine, it has the right checksum. But the mirror for some reason is on a list containing malicious websites.

When do you need this to be done by? (YYYY/MM/DD)


Screenshot_from_2020-10-29_20-04-51.png


The checksum file is correct, and the first 25 or so meg of the ISO matches my already downloaded and verified ISO. I only have 3 Mbit DSL, but I suspect the malware detection is faulty. Hopefully someone with a fast connection can download the whole thing and confirm.

Edit: If you've already downloaded the ISO, does the checksum match the checksum file?

I downloaded the iso, and the sha256 match to the one on the mirror. The sum is the same on other mirrors.

Can you verify the download sum to see if no one messed with it ?

 $ sha256sum Fedora-Workstation-Live-x86_64-33-1.2.iso 
582a825d564e2682334ac893c9160667c7f4578c0c8045a25ea534af7c13334b  Fedora-Workstation-Live-x86_64-33-1.2.iso

I also verified the signature, and it is good: https://getfedora.org/fr/security/

So, looks like google "safe browsing" which mozilla/firefox uses is misdetecting this. It may be due to some other issue with that mirror.

If you download from https://dl.fedoraproject.org/pub/fedora/linux/releases/33/Workstation/x86_64/iso/Fedora-Workstation-Live-x86_64-33-1.2.iso does it tell you the same thing?

Unfortunately, google seems to only accept reports of misdetection via their "google search console" and you have to control/be owner of the site in question, so I can't simply tell them they are wrong.

I checked the checksum of the file I downloaded from that mirror, it is:

582a825d564e2682334ac893c9160667c7f4578c0c8045a25ea534af7c13334b

which seems to be correct. So indeed a false positive. Sorry.
Still the mirror should be removed or be put back on the google whitelist

Actually it seems already fixed? I can't get the banner here... and:

https://transparencyreport.google.com/safe-browsing/search?url=http:%2F%2Flaotzu.ftp.acc.umu.se%2Fmirror%2Ffedora%2Flinux%2Freleases%2F33%2FWorkstation%2Fx86_64%2Fiso%2FFedora-Workstation-Live-x86_64-33-1.2.iso

shows:

Current status
check_circle
No unsafe content found

So perhaps it was not live too long. ;)

Thanks in any case for the report! We appreciate you being vigilant and letting us know things like this!

Metadata Update from @kevin:
- Issue close_status updated to: Fixed
- Issue status updated to: Closed (was: Open)

Metadata