Virus/ malware/ data leak in CN ?

liviudo
Posts: 12
Joined: Wed Jun 06, 2012 4:52 pm
Contact:

Virus/ malware/ data leak in CN ?

Postby liviudo » Thu May 08, 2014 8:53 pm

Virus? Malware?
Why 2 internet connections (wordpress.com and 192.185.41.192)?
Application rated as untrusted by Agnitum?
Attachments
cn-2.jpg
192.185.41.192
cn-2.jpg (34.95 KiB) Viewed 8315 times
cn-1.jpg
wordpress.com
cn-1.jpg (43.37 KiB) Viewed 8315 times
User avatar
CintaNotes Developer
Site Admin
Posts: 5002
Joined: Fri Dec 12, 2008 4:45 pm
Contact:

Re: Virus/ malware/ data leak in CN ?

Postby CintaNotes Developer » Thu May 08, 2014 11:47 pm

Hi Livuido,

thanks for your message!
Obvious question but still: did you download CN from cintanotes.com or from some other site?
Alex
liviudo
Posts: 12
Joined: Wed Jun 06, 2012 4:52 pm
Contact:

Re: Virus/ malware/ data leak in CN ?

Postby liviudo » Fri May 09, 2014 2:37 am

I use the portable version from portableapps.com
I will try with cintanotes.com portable version.
Can you check on your side to install Agnitum Outpost if you have the same results?

Liviu
User avatar
CintaNotes Developer
Site Admin
Posts: 5002
Joined: Fri Dec 12, 2008 4:45 pm
Contact:

Re: Virus/ malware/ data leak in CN ?

Postby CintaNotes Developer » Fri May 09, 2014 3:04 am

Thanks for the info!
I'll check it with Outpost and get back to you asap.
Alex
liviudo
Posts: 12
Joined: Wed Jun 06, 2012 4:52 pm
Contact:

Re: Virus/ malware/ data leak in CN ?

Postby liviudo » Mon May 12, 2014 2:19 am

192.185.41.192 seems to be used for cintanotes updates.

I don't know what the registry key with "ProxyEnable" means.

192.0.84.247 is used for SimpleNotes sync.

What wordpress.com has to do with these? I don't know.
(Maybe for portableapps.com updates ?)

Liviu

PS: I used CN portable zip 2.5.1 version from CintaNotes.com
Attachments
cn-7-0.jpg
cn-7-0.jpg (58.65 KiB) Viewed 8268 times
cn-6.jpg
cn-6.jpg (49.02 KiB) Viewed 8268 times
cn-5.jpg
cn-5.jpg (107.29 KiB) Viewed 8268 times
reza
Posts: 11
Joined: Sat Mar 30, 2013 7:19 pm
Contact:

Re: Virus/ malware/ data leak in CN ?

Postby reza » Mon May 12, 2014 10:12 pm

As far as Simplenote goes, it is owned by the WordPress people (Automattic)
liviudo
Posts: 12
Joined: Wed Jun 06, 2012 4:52 pm
Contact:

Re: Virus/ malware/ data leak in CN ?

Postby liviudo » Wed May 14, 2014 2:09 am

Maybe you're right ... and I have too many concerns for nothing ...
User avatar
CintaNotes Developer
Site Admin
Posts: 5002
Joined: Fri Dec 12, 2008 4:45 pm
Contact:

Re: Virus/ malware/ data leak in CN ?

Postby CintaNotes Developer » Thu May 22, 2014 12:45 pm

We've installed Outpost and we only have registered the outgoing connections to:

192.185.41.192 : 80 - cintanotes.com (CN updates)
192.0.84.247 : 443 - api.simperium.com (Simplenote sync)

ProxyEnable is connected with WinInet which CN uses.

We haven't witnessed attempts to connect to "wordpress.com". But indeed Simplenote is made by Automaticc, owners of WordPress.
No way to tell for sure till we can reproduce this.

About the "untrusted" status, we'll contact Agnitum so that they register our code signing certificate with their database.
Alex

Return to “CintaNotes Personal Notes Manager”