back
96 comments
7zip.com has never been the official website of the project. It's been 7-zip.org
How can the average 7zip user know which one it is?

Search results can be gamed by SEO, there were also cases of malware developers buying ads so links to the malware download show up above legitimate ones. Wikipedia works only for projects prominent enough to have a Wikipedia page.

What are the other mechanisms for finding out the official website of a software?

There is normally a wiki page for every popular program which normally contains an official site URL. That's how I remember where to actually get PuTTY. Wiki can potentially be abused if it's a lesser known software, but, in general, it's a good indicator of legitimacy.
> How can the average 7zip user know which one it is?

I dunno, if you type "download 7zip" into Google, the top result is the official website.

Also, 7zip.com is nowhere on the first page, and the most common browsers show you explicitly it's a phishing website.

This is actually a pretty good case of the regular user being pretty safe from downloading malware.

Fails to load for me with: "The page was blocked because of a matching filter in uBlock filters – Badware risks."

Which is enabled by default in uBlock. And installing it is pretty much a standard suggestion for any web user.

How would you ensure that the "average user" actually gets to the page he expects to get to?

There are risks in everything you do. If the average user doesn't know where the application he wants to download _actually_ comes from then maybe the average user shouldn't use the internet at all?

Open source software will have a code repo with active development happening on it. That repo will usually link to official Web page and download places.
1. Go to the wikipedia article on 7-Zip

2. Go the listed homepage

Avoid downloading stuff of internet and avoid search engines.

In a post AI world asking how not be scammed is hard cause now everything can be faked.

Trust what you definitely know but still verify.

Especially in the next 5-10 years that's going to become the reality so I guess sit tight and prepare for the waves and sunamis of scams.

open About in the app?
I tested with the 3 major browsers and all 3 block it as "Suspected Phishing". So looks like the system is working as designed.

Lookalike websites serving malware have always existed. So this isn't exactly news. But the browsers are blocking them like they should.

Weirdly, in Firefox 7zip.com is blocked but www.7zip.com isn't. If you type '7zip' in the address bar and then press Ctrl+Enter to go to the address, you'll get owned, because that key-combo adds the www at the beginning.
Yes, and I think this case gets somewhat more notoriety because the phishing site has the .com domain and the legitimate one has a .org.

Like it or not, .com adds perceived trustworthiness and works as a branding signal, especially in these times of VCs throwing large amounts of money at branding and buying 3 to 6 letter .com domains, but a small project like 7zip cannot afford that kind of expense.

This has been a long-standing problem with 7-Zip.

An article from 2018:

https://www.bleepingcomputer.com/news/security/fake-websites...

And uBlock Origin's "Badware" filter blocks it:

https://github.com/uBlockOrigin/uAssets/blob/master/filters/...

The links to the file downloads on 7zip.com all point to 7-zip.org. Example: https://www.7-zip.org/a/7z2501-x64.exe

Did they change it because of the negative publicity (Reddit) and will probably change back soon to the malware links?

Maybe that's how they don't get banned by their hosting provider. Once reports start coming in, they pretend to be a honest establishment.
As a Linux user, used to get all of my software either through the distro's repository or Flathub, having to download software from sites when I run Windows makes me feel really queasy.
winget ftw
Does the 7-Zip author still refuse to digitally sign or even provide hashes of the official downloads? It's an extremely weird flex, he thinks it's a frivolous waste of time or something.
He's always been an odd one, for a long time he refused to enable even basic hardening features like ASLR and DEP because they made the executables slightly larger. He eventually relented on some of those, but last I heard the more advanced mitigations like HE-ASLR, CFG and GS were still disabled.
Even more, there are regularly security vulnerabilities patched in releases that don't get CVEs and don't get any mention in patch notes, there are no incremental commits between releases, just giant code dumps. There's no changelog linked on the 7-zip.org website. There's no auto-update or update check mechanism, which is problematic for a project with regular CVEs whose primary purpose is handling untrusted inputs.

7-zip is not a serious project and its use should be strongly discourged.

I migrated from 7-Zip to NanaZip, a fork with modern Windows features that the original developer refuses to implement.

https://github.com/M2Team/NanaZip

Whenever I see "modern Windows experience", it always turns to be worse than the original one.
Windows 11 has 7-zip support built in.
No update for a year for something that opens weird files from the internet is a little scary, even just dependency changes. Not that 7-zip was ever any better at that.
modern windows features?

I imagine an electron rewrite, with DirectX 12 and Copilot buttons everywhere

Do people even double check installers are digitally signed? There's so much open source stuff out there that is not digitally signed, most people might not even notice.
The .com site serving malware aside, it's how people even get to downloading this. PC builder [...], USB stick [...], YouTube tutorial for a new build [...] instructed to download. Makes me wonder, is this how "PC builders" build PCs, or was this a regular user person. Archive managers are such basic software that I'd think surely someone would keep a stash of (trusted) installer files for the basic tools to be installed in a new environment. At least that's what we used to do, like, 25 years ago. Or use choco, winget or whatever. Malware hygiene habits remain almost unchanged - don't click that link.
It says the code signing cert has been revoked by now.

How does verification work? Only at installation time or will it prevent running the installed files later if installation happened when the cert was still accepted?

Linux user asking out of curiousity...

I've started using winget to install my apps for exactly this reason. I can't keep track of every url for every piece of software.
Is that safe? Microsoft's policy [1] seems to say that anyone can publish an update to a package as long as it passes "an automated process" which checks that it's "not known to be malicious".

[1] https://learn.microsoft.com/en-us/windows/package-manager/pa...

The only solutions for the malicious domain would be lawsuits or hactivism. As others have said it is blocked in uBlock by default which everyone should be using at a bare minimum.
I usually check some other reliable source for official web address. Earlier I used Wikipedia. Recently found out Softorage, so using that nowadays.
It doesnt help that many services use a few domain names, bonus points if other ones look like from scam domain examples
I always go through Wikipedia if I want to download software for this exact reason.
i'm increasingly convinced nothing good ever comes from youtube tutorials
The recent openclaw videos are the best. “Ten openopenclaw skills that will change your life!” Ends up being useless YouTube metrics and a glorified egg drop.
remember when we could downvote the bad ones?
I would not trust any sw from Russia. Could be a vector for the FSB. I'm sure they have thought about it.
The same could be said for software from the US. Could be a vector of CIA. For average US citizens, it might even be safer to use Russian software because FSB can't come after them.
I compared https://7-zip.org/a/7z2600-x64.exe with https://7-zip.com/a/7z2600-x64.exe. They are byte-for-byte identical. If there's malware, it isn't obvious.
The OP refers to 7zip.com, no dash. Those dashed domains directly resolve to the same Hetzner server, but the undashed one heads off into Cloudflare.
Seems this all comes down to the wrong domain (.org vs .com).