Boost logo

Boost Users :

Subject: Re: [Boost-users] Is it safe to download boost_1_67_0-msvc-14.1-64.exe?
From: Tom Kent (lists_at_[hidden])
Date: 2018-06-25 22:05:47


On Fri, Jun 22, 2018 at 2:45 PM, Good Guy via Boost-users <
boost-users_at_[hidden]> wrote:

> On 08/06/2018 22:33, Trung Tran via Boost-users wrote:
>
>> From https://dl.bintray.com/boostorg/release/1.67.0/binaries/
>> boost_1_67_0-msvc-14.1-64.exe
>> I got windows defender warning on Trojan:Win32/Vigorf.A
>> Total virus report the same on the same file.
>> https://www.virustotal.com/#/file/402d07022fe9671e401efc4e90
>> a1ff25e1bc9e1c23b3d8b1c65e4a2e6799abfc/detection
>>
>
> The link is provided on Boost's official download page <
> https://www.boost.org/users/download/> so you have to take it on trust.

Please don't take it on trust. If you get a warning for the binaries, check
the hashes, then check the signature on the hashes!

Boost (esp the binaries) would be an ideal target for a malicious actor to
hack and make changes to that then get built into everybody's code.
However, this type of attack definitely wouldn't trigger virus scanners, so
I'm not worried about these reports (and since others previously in the
thread have verified the checksums match).

Tom



Boost-users list run by williamkempf at hotmail.com, kalb at libertysoft.com, bjorn.karlsson at readsoft.com, gregod at cs.rpi.edu, wekempf at cox.net