Page 1 of 1
Virus/ malware/ data leak in CN ?
Posted: Thu May 08, 2014 8:53 pm
by liviudo
Virus? Malware?
Why 2 internet connections (wordpress.com and 192.185.41.192)?
Application rated as untrusted by Agnitum?
Re: Virus/ malware/ data leak in CN ?
Posted: Thu May 08, 2014 11:47 pm
by CintaNotes Developer
Hi Livuido,
thanks for your message!
Obvious question but still: did you download CN from cintanotes.com or from some other site?
Re: Virus/ malware/ data leak in CN ?
Posted: Fri May 09, 2014 2:37 am
by liviudo
I use the portable version from portableapps.com
I will try with cintanotes.com portable version.
Can you check on your side to install Agnitum Outpost if you have the same results?
Liviu
Re: Virus/ malware/ data leak in CN ?
Posted: Fri May 09, 2014 3:04 am
by CintaNotes Developer
Thanks for the info!
I'll check it with Outpost and get back to you asap.
Re: Virus/ malware/ data leak in CN ?
Posted: Mon May 12, 2014 2:19 am
by liviudo
192.185.41.192 seems to be used for cintanotes updates.
I don't know what the registry key with "ProxyEnable" means.
192.0.84.247 is used for SimpleNotes sync.
What wordpress.com has to do with these? I don't know.
(Maybe for portableapps.com updates ?)
Liviu
PS: I used CN portable zip 2.5.1 version from CintaNotes.com
Re: Virus/ malware/ data leak in CN ?
Posted: Mon May 12, 2014 10:12 pm
by reza
As far as Simplenote goes, it is owned by the WordPress people (Automattic)
Re: Virus/ malware/ data leak in CN ?
Posted: Wed May 14, 2014 2:09 am
by liviudo
Maybe you're right ... and I have too many concerns for nothing ...
Re: Virus/ malware/ data leak in CN ?
Posted: Thu May 22, 2014 12:45 pm
by CintaNotes Developer
We've installed Outpost and we only have registered the outgoing connections to:
192.185.41.192 : 80 - cintanotes.com (CN updates)
192.0.84.247 : 443 - api.simperium.com (Simplenote sync)
ProxyEnable is connected with WinInet which CN uses.
We haven't witnessed attempts to connect to "wordpress.com". But indeed Simplenote is made by Automaticc, owners of WordPress.
No way to tell for sure till we can reproduce this.
About the "untrusted" status, we'll contact Agnitum so that they register our code signing certificate with their database.