DoodlesTheBob

Member
Aug 23, 2018
302
429
This hasn't been my experience with Windows Defender. I check everything I download from the internet with it and never had it act out, with the exception of Cheat Engine. It makes sense that WD detects it as a potential threat since it's a memory editor.


That is possible of course, but it's the first time in this thread at least that multiple people detected a threat inside a new release.
It's not just possible. I've verified it myself. I have the waterfox fork, noscript and ublock origin. I always get the .rar or .zip on the first try with gofile. I get NoScript XSS warnings. Guess what XSS is?

On my chrome, it's virgin. Only installed for programs that use it as a dependency. If I open the same gofile link in chrome, it attempts to download the MSI installer instead of the zip/rar. If I open a private tab, I'll get offered a MSI installer or an EXE installer.

This is gofile allowing their ad providers to run code on their site. Said code directs you to a downloader file to a virus-attached version of the files.
 
  • Like
Reactions: ihatefleas

DoodlesTheBob

Member
Aug 23, 2018
302
429
It's not just possible. I've verified it myself. I have the waterfox fork, noscript and ublock origin. I always get the .rar or .zip on the first try with gofile. I get NoScript XSS warnings. Guess what XSS is?

On my chrome, it's virgin. Only installed for programs that use it as a dependency. If I open the same gofile link in chrome, it attempts to download the MSI installer instead of the zip/rar. If I open a private tab, I'll get offered a MSI installer or an EXE installer.

This is gofile allowing their ad providers to run code on their site. Said code directs you to a downloader file to a virus-attached version of the files.
In fact, anonfiles does it too. Notice it even apes the anonfiles icon. 1687009535049.png

Notice it's .zip.vhd. Yet the URL is sysianedukeration.info?
 

DoodlesTheBob

Member
Aug 23, 2018
302
429
In fact, anonfiles does it too. Notice it even apes the anonfiles icon. View attachment 2703665

Notice it's .zip.vhd. Yet the URL is sysianedukeration.info?
And likewise... with gofile, you can see I'm served both the file and a redirect.

1687009770406.png

A pair of ad-partners for the file sites are being naughty naughty. F95 uploaders aren't to blame. Do not trust vhd, exe or msi filetypes when you KNOW you're expecting a 1+ gigabyte zip/rar.
 

ihatefleas

Member
Dec 18, 2018
163
337
It's not just possible. I've verified it myself. I have the waterfox fork, noscript and ublock origin. I always get the .rar or .zip on the first try with gofile. I get NoScript XSS warnings. Guess what XSS is?

On my chrome, it's virgin. Only installed for programs that use it as a dependency. If I open the same gofile link in chrome, it attempts to download the MSI installer instead of the zip/rar. If I open a private tab, I'll get offered a MSI installer or an EXE installer.

This is gofile allowing their ad providers to run code on their site. Said code directs you to a downloader file to a virus-attached version of the files.
Yeah, I'm aware of these kind of hijacks and misdirects. However, they are also nothing new, in fact every thread should be full of reports that a file contains a threat if it's just that since many file hosts are rather shady and dangerous to use without noscript and an adblock.

Or, to ask it the other way around: Why haven't the same people that don't have an adblock + noscript running complained the previous 10+ releases? I don't think that these kinds of attacks are uncommon.
 

DoodlesTheBob

Member
Aug 23, 2018
302
429
Yeah, I'm aware of these kind of hijacks and misdirects. However, they are also nothing new, in fact every thread should be full of reports that a file contains a threat if it's just that since many file hosts are rather shady and dangerous to use without noscript and an adblock.

Or, to ask it the other way around: Why haven't the same people that don't have an adblock + noscript running complained the previous 10+ releases? I don't think that these kinds of attacks are uncommon.
Because the trusted site isn't actually in on the scam and doesn't condone it. Usually, people have to report it to the host that it is happening and then the host has to figure out which ad partner is doing it and the host eliminates that ad partner. Or worse, the host has to complain to the ad network or switch ad networks to shed the bad advertiser that is malicious.

What I'm saying is, these "issues" can exist for a couple hours, or a couple days, or a couple weeks, and because the bad actors are in a ad-rotation, maybe only 1 out of 20 downloaders are getting the flim-flam switcharoo bullshit.

Best thing we can do is let gofile and let anonfile know that one of their ad partners is doing an injection attack and they'll take care of it.
 
  • Like
Reactions: ihatefleas

Trart1965

New Member
Mar 18, 2020
8
21
Here is a torrent
File directly downloaded from the gofile
Please seed
Yup, MD5 checksum in the torrent matches checksum on gofile: 46F0BD4E7FEF6C83911F8049CA8E0540 - but this only proves that files are identical (so theoretically they could be modified before the upload). So there's little sense in such verification, unless dev himself provides checksum for original file on download page.
 

Kedr76

New Member
Nov 9, 2020
4
27
WildLife-2023.06.16
You don't have permission to view the spoiler content. Log in or register now.
rpdl torrents are unaffiliated with F95Zone and the game developer.
Please note that we do not provide support for games.
For torrent-related issues use here, or join us on !
, . Downloading issues? Look here.​
there is no one here for distribution
 
  • Like
Reactions: cupf

papajtfc

New Member
Feb 8, 2020
2
0
any way to make maya's body to look like shey's? can anyone share their maya preset if there's any. thanks a bunch!
 
3.80 star(s) 176 Votes