mirror of
https://github.com/go-gitea/gitea.git
synced 2026-03-15 20:52:52 -05:00
gitea is a Trojan? can the author explain? #5150
Closed
opened 2025-11-02 06:16:02 -06:00 by GiteaMirror
·
9 comments
No Branch/Tag Specified
main
release/v1.25
release/v1.24
release/v1.23
release/v1.22
release/v1.21
release/v1.20
release/v1.19
release/v1.18
release/v1.17
release/v1.16
release/v1.15
release/v1.14
release/v1.13
release/v1.12
release/v1.11
release/v1.10
release/v1.9
release/v1.8
v1.25.3
v1.25.2
v1.25.1
v1.25.0
v1.24.7
v1.25.0-rc0
v1.26.0-dev
v1.24.6
v1.24.5
v1.24.4
v1.24.3
v1.24.2
v1.24.1
v1.24.0
v1.23.8
v1.24.0-rc0
v1.25.0-dev
v1.23.7
v1.23.6
v1.23.5
v1.23.4
v1.23.3
v1.23.2
v1.23.1
v1.23.0
v1.23.0-rc0
v1.24.0-dev
v1.22.6
v1.22.5
v1.22.4
v1.22.3
v1.22.2
v1.22.1
v1.22.0
v1.23.0-dev
v1.22.0-rc1
v1.21.11
v1.22.0-rc0
v1.21.10
v1.21.9
v1.21.8
v1.21.7
v1.21.6
v1.21.5
v1.21.4
v1.21.3
v1.21.2
v1.20.6
v1.21.1
v1.21.0
v1.21.0-rc2
v1.21.0-rc1
v1.20.5
v1.22.0-dev
v1.21.0-rc0
v1.20.4
v1.20.3
v1.20.2
v1.20.1
v1.20.0
v1.19.4
v1.21.0-dev
v1.20.0-rc2
v1.20.0-rc1
v1.20.0-rc0
v1.19.3
v1.19.2
v1.19.1
v1.19.0
v1.19.0-rc1
v1.20.0-dev
v1.19.0-rc0
v1.18.5
v1.18.4
v1.18.3
v1.18.2
v1.18.1
v1.18.0
v1.17.4
v1.18.0-rc1
v1.19.0-dev
v1.18.0-rc0
v1.17.3
v1.17.2
v1.17.1
v1.17.0
v1.17.0-rc2
v1.16.9
v1.17.0-rc1
v1.18.0-dev
v1.16.8
v1.16.7
v1.16.6
v1.16.5
v1.16.4
v1.16.3
v1.16.2
v1.16.1
v1.16.0
v1.15.11
v1.17.0-dev
v1.16.0-rc1
v1.15.10
v1.15.9
v1.15.8
v1.15.7
v1.15.6
v1.15.5
v1.15.4
v1.15.3
v1.15.2
v1.15.1
v1.14.7
v1.15.0
v1.15.0-rc3
v1.14.6
v1.15.0-rc2
v1.14.5
v1.16.0-dev
v1.15.0-rc1
v1.14.4
v1.14.3
v1.14.2
v1.14.1
v1.14.0
v1.13.7
v1.14.0-rc2
v1.13.6
v1.13.5
v1.14.0-rc1
v1.15.0-dev
v1.13.4
v1.13.3
v1.13.2
v1.13.1
v1.13.0
v1.12.6
v1.13.0-rc2
v1.14.0-dev
v1.13.0-rc1
v1.12.5
v1.12.4
v1.12.3
v1.12.2
v1.12.1
v1.11.8
v1.12.0
v1.11.7
v1.12.0-rc2
v1.11.6
v1.12.0-rc1
v1.13.0-dev
v1.11.5
v1.11.4
v1.11.3
v1.10.6
v1.12.0-dev
v1.11.2
v1.10.5
v1.11.1
v1.10.4
v1.11.0
v1.11.0-rc2
v1.10.3
v1.11.0-rc1
v1.10.2
v1.10.1
v1.10.0
v1.9.6
v1.9.5
v1.10.0-rc2
v1.11.0-dev
v1.10.0-rc1
v1.9.4
v1.9.3
v1.9.2
v1.9.1
v1.9.0
v1.9.0-rc2
v1.10.0-dev
v1.9.0-rc1
v1.8.3
v1.8.2
v1.8.1
v1.8.0
v1.8.0-rc3
v1.7.6
v1.8.0-rc2
v1.7.5
v1.8.0-rc1
v1.9.0-dev
v1.7.4
v1.7.3
v1.7.2
v1.7.1
v1.7.0
v1.7.0-rc3
v1.6.4
v1.7.0-rc2
v1.6.3
v1.7.0-rc1
v1.7.0-dev
v1.6.2
v1.6.1
v1.6.0
v1.6.0-rc2
v1.5.3
v1.6.0-rc1
v1.6.0-dev
v1.5.2
v1.5.1
v1.5.0
v1.5.0-rc2
v1.5.0-rc1
v1.5.0-dev
v1.4.3
v1.4.2
v1.4.1
v1.4.0
v1.4.0-rc3
v1.4.0-rc2
v1.3.3
v1.4.0-rc1
v1.3.2
v1.3.1
v1.3.0
v1.3.0-rc2
v1.3.0-rc1
v1.2.3
v1.2.2
v1.2.1
v1.2.0
v1.2.0-rc3
v1.2.0-rc2
v1.1.4
v1.2.0-rc1
v1.1.3
v1.1.2
v1.1.1
v1.1.0
v1.0.2
v1.0.1
v1.0.0
v0.9.99
Labels
Clear labels
$20
$250
$50
$500
backport/done
💎 Bounty
docs-update-needed
good first issue
hacktoberfest
issue/bounty
issue/confirmed
issue/critical
issue/duplicate
issue/needs-feedback
issue/not-a-bug
issue/regression
issue/stale
issue/workaround
lgtm/need 2
modifies/api
modifies/translation
outdated/backport/v1.18
outdated/theme/markdown
outdated/theme/timetracker
performance/bigrepo
performance/cpu
performance/memory
performance/speed
pr/breaking
proposal/accepted
proposal/rejected
pr/wip
pull-request
reviewed/wontfix
💰 Rewarded
skip-changelog
status/blocked
topic/accessibility
topic/api
topic/authentication
topic/build
topic/code-linting
topic/commit-signing
topic/content-rendering
topic/deployment
topic/distribution
topic/federation
topic/gitea-actions
topic/issues
topic/lfs
topic/mobile
topic/moderation
topic/packages
topic/pr
topic/projects
topic/repo
topic/repo-migration
topic/security
topic/theme
topic/ui
topic/ui-interaction
topic/ux
topic/webhooks
topic/wiki
type/bug
type/deprecation
type/docs
type/enhancement
type/feature
type/miscellaneous
type/proposal
type/question
type/refactoring
type/summary
type/testing
type/upstream
Mirrored from GitHub Pull Request
No Label
type/question
Milestone
No items
No Milestone
Projects
Clear projects
No project
No Assignees
Notifications
Due Date
No due date set.
Dependencies
No dependencies set.
Reference: github-starred/gitea#5150
Reference in New Issue
Block a user
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Delete Branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Originally created by @VeniVidiVici9 on GitHub (Mar 30, 2020).
183.192.179.16
182.254.52.17
14.18.182.223
61.241.50.63
101.89.19.140
113.96.198.54
59.36.132.240
14.215.156.146
What do these address authors do?
It's like a Trojan. My firewall keeps alarming?
It always connect these addresses silently in the background, can the author explain?
This is the latest version
@lunny commented on GitHub (Mar 30, 2020):
Where did you download the gitea binary? And what's the version? Have you compared the checksum?
@VeniVidiVici9 commented on GitHub (Mar 30, 2020):
I downloaded a docker image, not a binary file,
Downloaded on this site: https://hub.docker.com,
sha256: 306e7b99e8c6f2f49c43f7ad072904b1eb741bde8314093b7cb4ffe51be508d8
The following is the mirror information:
maintainer maintainers@gitea.io
org.label-schema.build-date 2020-03-19T21: 49: 12Z
org.label-schema.schema-version 1.0
org.label-schema.vcs-ref
7225453d5forg.label-schema.vcs-url https://github.com/go-gitea/gitea.git
@techknowlogick commented on GitHub (Mar 30, 2020):
Do you have federated avatars enabled? Can you give more details about those connections being made (for example what port is being connected to)?
@Monter commented on GitHub (Mar 30, 2020):
Do you have any migrations (mirrors) in the repo? I have a lot of them and freshly after starting Gitea immediately tries to refresh them all, which pisses me off and almost kills the CPU in the server.
Strange outgoing connections can come from descriptions of a given repo into which their authors throw various pictures, graphics, links, etc.
@VeniVidiVici9 commented on GitHub (Mar 31, 2020):
My situation is similar to yours, I also encountered a situation similar to illegal login,such as belowing:
------------------ 原始邮件 ------------------
发件人: "Mark eM"<notifications@github.com>;
发送时间: 2020年3月30日(星期一) 晚上10:03
收件人: "go-gitea/gitea"<gitea@noreply.github.com>;
抄送: "104561102"<104561102@qq.com>;"State change"<state_change@noreply.github.com>;
主题: Re: [go-gitea/gitea] gitea is a Trojan? can the author explain? (#10888)
Do you have any migrations in the repo? I have a lot of them and freshly after starting Gitea immediately tries to refresh them all, which pisses me off and almost kills the CPU in the server.
Strange outgoing connections can come from descriptions of a given repo into which their authors throw various pictures, graphics, links, etc.
—
You are receiving this because you modified the open/close state.
Reply to this email directly, view it on GitHub, or unsubscribe.
@VeniVidiVici9 commented on GitHub (Mar 31, 2020):
Yes, I have the federated avatars enabled, these connections communicate via http port 3000 by default.
I also encountered a situation similar to illegal login,such as belowing:
=========================================================================================================================================================
Do you have federated avatars enabled? Can you give more details about those connections being made (for example what port is being connected to)?
—
You are receiving this because you modified the open/close state.
Reply to this email directly, view it on GitHub, or unsubscribe.
@VeniVidiVici9 commented on GitHub (Mar 31, 2020):
I use a container, not a binary file, and the version number is: 1.12.0 + dev-69-g972b3bf3b.
checksum is sha256:c4a654eb05c032eac9ee57de853c725de6169f93f0a45ccd506c7bf4bed03fe5
I have compared the information in the build log.
The checksum is the same on the Docker Hub official website server.
Checksum on Docker Hub official website server:
and the following is my build image log:
I encountered a situation similar to illegal login,such as belowing:
================================================================================================================================
Where did you download the gitea binary? And what's the version? Have you compared the checksum?
—
You are receiving this because you authored the thread.
Reply to this email directly, view it on GitHub, or unsubscribe.
@Monter commented on GitHub (Mar 31, 2020):
Please stop spamming and cut out unnecessary items and headers before posting.
@lunny commented on GitHub (Mar 31, 2020):
As @lafriks said, Gitea will not visit other special external sites. If you care about that, you can compile the binary or docker from source.