Skip to content
View in the app

A better way to browse. Learn more.

The AVSIM Community

A full-screen app on your home screen with push notifications, badges and more.

To install this app on iOS and iPadOS
  1. Tap the Share icon in Safari
  2. Scroll the menu and tap Add to Home Screen.
  3. Tap Add in the top-right corner.
To install this app on Android
  1. Tap the 3-dot menu (⋮) in the top-right corner of the browser.
  2. Tap Add to Home screen or Install app.
  3. Confirm by tapping Install.

SquawkWin: The Community's First Trojan Horse?

Featured Replies

XP doesn't come with Alexa or any other spyware or malware when delivered by Microsoft to retailers and OEMs.Some OEMs DO install spyware (knowingly or not) like Alexa though in an effort to give the buyer a "better experience".Same with some ISPs whose installation disks install all kinds of browser plugins (including Alexa, Bonzy buddie, etc. etc.) without asking.

  • Replies 120
  • Views 13.8k
  • Created
  • Last Reply

Top Posters In This Topic

the only reason would be to doublecheck on the data being sent (to find out why a login you expect to succeed fails, did you send the wrong data?).Personally I'd never send it anywhere but place it in a local logfile on the machine the software is run on though, and even then make that something I'd be sure to either remove in the release version or make optional via a configuration setting (which would be turned off by default).

Think of what could have happend if a system Adim had logged on to one of the networks to test this, using there adim ID and password with out thinking, and then that data got sent back to who ever is behind SquawkWin, and Avsim had not done the out standing job tracking this problem down. It could have opened up a realy big hole in the system. Anyone remember when we all got new passwords last year because of some one trying to hacking the system? Maybe its the same people.Or maybe this has been a big misunderstanding. Until the Sun Team tells us who they really are this may never be answered.

Seems like their forums are "down" again.Thomas NyheimChief Pilot, UVAVA-Director/Events NY-ARTCC

Thomas,Forum still working for me, as of 1330 Central on the 3rd.Greg P

I would compliment the work done and information passed to me here in this issue.Compiling lists of users and data is not an honorable thing to do. Also this flies in the face of the spirit of Flight Simming I think.If unchecked this could become a serious threat to freeware, shareware and even payware.Since the days of add ons to FS5 or 4 for that matter, I have placed high value on the planes and such that I cannot program. Sure I used Mallard's Aircraft and adventure factory long ago, and now I use Abacus and Gmax on a limited level unworthy of uploading, but I have a little understanding of what goes into that P-51B I got for little cost.It matters little to me if this software is called "spyware" a "trojan" or whatever, it clearly violates the implied trust of one that would download and use it. An awful lot of money can be made from "user lists". Let alone the question of what would the ethics of the buyers be?Thakns to all that did the work and kept me and my friends informed about an issue of some importance.Jimh2

I don't understand what the fuss is all about...1. SquawkWin has been STEALING personal info and sending it back to its developers - TheSunTeam.2. Initially, TheSunTeam denied this now-obvious fact. That was a LIE.3. They NEVER told us WHY they STOLE our peronal info in the first place.4. They NEVER told us WHO REALLY FORMS THE SUN TEAM.I'm asking you: WHY in the name of God would any of us EVER trust ANYTHING coming from them in the future?Better yet, why would ANY of us try an ANONYMOUS piece of software coming from ANONYMOUS developers - because that's exactly what SquawkWin is. Everybody complains about viruses, trojans, etc. yet we are blindly running a piece of unknown software coming from an anonymous group.Would you run the same piece of software if it was named "TrojanWin.exe" coming from "TheAngelOfDeath" group? I guess not.We are lucky that seemingly SquawkWin only stole useless personal info, and that it was caught in time before potentially managing to do some damage to the virtual ATC networks.Let's be more careful next time.My 2c,AlPS: If you decided to uninstall it, make sure you run some anti-spyware tool to check for "leftovers".

>>I'm asking you: WHY in the name of God would any of us EVER trust ANYTHING coming from them in the future?I've puzzled over this myself too. There are those who seem fanatical about their business practices. At first I thought those who're on the other side of the fence are actually people from their own team creating multiple usernames and saying the same illogical things.The other more likely reason is the notion of playing the role of the martyr. Here we have popular network pointing out obvious problems, and we have the underdog appearing to be 'bullied' (far from the truth, but an easy thing to subscribe to). It is a very, very attractive notion for a small minority of folks, especially those who think others owe them, to come to their defence and adopt the 'stick it to THE MAN!' mode of operation, and that's what I believe is happening.

Stupid Logic 1: Stealing of passoword. What's stealing? How many of you know who "owns" the servers donated to vatsim and ivao? Do you know the "owners" retain the root password of the unix machine and its no brainer for them to take a "look" at the cert.txt and .conf file?? You can be a user of their network and like a holy joe come forward to donate a server then after a few days disconnect it and there you are..with conf file, cert.txt actual s/w et al. If I wanted as a pilot a superior service I should and must give all data related to it. I care two hoots if the network people have kept their network vulnerable.Stupid Logic 2: Statements like what if they stole some admins or sups password? May I ask what if?? Big deal? All the network gurus have designed is a system where a "pilot" a "contoller" a "supervisor" and an "admin can share the same userid and password!!! If the administrators are stupid to that extent why blame others!! As a pilot i love this software and i want to use it. If the gurus designed a stupid system of certification let them suffer. My pilot user id and password are only thing in this godammed world is used to let me fly online and therefore i'll give it to anyone who lets me fly online better....its not my personal info!!!!! its only two sets of numbers allowing me to fly online...its not my email and neihter its my ssn or my ccn!!Suppose I tell you that initially when the software was developed "officially" it was decided that a beta will be realesed to a select few and to check that these testers did not give it to others and to check their version is use to match with the bug list report, that this provision was kept. Later when it became a "third" party s/w the developers forgot all about this feature...will it not be more plausible then terming them as "trojan" creators!!The sad fact is both the networks have become "proprietory" and personal fiefdoms of a select few. The original developers of fsd and squakbox kept it open and GNU but people deliberatley made changes to make it "closed" so now anybody who threatens to open it gets banished. As one of the largest online community we must fight against such protectionism!! Today, my controller client in ivao does not work in vatsim, my voice client does not work and soon my pilot client wont either and yes i see "pilots" taking sides with people who claim "tojans"

>Stupid Logic 1: Stealing of passoword.What is stealing? Stealing is taking something from somebody without his/her permission. It is not important WHAT one steals. The act is still STEALING (ignoring the word "stupid" for now)>Stupid Logic 2: Statements like what if they stole some admins>or sups password?So you agree that they STOLE? So your "Stupid Logic 1" is not valid? Thought so. LOL.In your Stupid Logic 2 you actually say "Hey. Everybody CAN steal, so it's OK if somebody ACTUALLY STEALS. Now THAT's a classical "stupid logic".Hmmm. It seems that you KNOW quite a lot about what was going on - that would make you a part of TheSunTeam . And allow me to ignore the "stupid excuse" of "forgetting the trojan code in". We're not THAT "stupid". Oh, and if you base yourself on what they say after they were caught red-handed, you forgot to put up your "LIAR" filter and think before you buy.Go on and use SquawkTrojanWin to your content. You really DESERVE it .With pity,Al

"Hmmm. It seems that you KNOW quite a lot about what was going on - that would make you a part of TheSunTeam"LOL! I can only say you very have fertile imagination!! Rest I wont reply else this forum will become quickly a personal flaming match between you and me. Just think about it "they" took my CID/VID and the assocaited 6 digit number and gave me a good pilot client to fly with, i cant think of a better use of those digits!!

>"Hmmm. It seems that Just think about it "they">took my CID/VID and the assocaited 6 digit number and gave me>a good pilot client to fly with, i cant think of a better use>of those digits!!Sadly it seems that it still does not bother you a little tiny bit that they took (stole) that personal info without even notifying you...Al

So you don't care why they took those informations, especially in the light of the fact that they were not needed on THEIR server? Simple question... Don't want to get involved in any flaming what so ever, just curious.Pittsburgh

I think everybody realized by now it was an oversight on their part and they rectified their mistake. Did they have malicious intent? Do you think programmers will resort to developing such a detailed programme just to take your CID/VID and associated password??There are far simpler ways to do it. Let me ask you a question in return? Are you happy with the SB Relay, SB, AVC and the associated harangue to connect? That PID/VID you have is just for this purpose to make your online flying better!! or are you happy as an online flyer that the community is becoming closed and proprietory by the day!!!Carelessness is not equal to maliciousness

>I think everybody realized by now it was an oversight on>their part and they rectified their mistake. Did they have>malicious intent? Do you think programmers will resort to>developing such a detailed programme just to take your CID/VID>and associated password??There are far simpler ways to do it.No - NOT EVERYBODY realized that it was an "Oversight". It's too late for THAT excuse. And strangely, it comes from a group who claims that they have the best and the mosyt professional team. Poor and lame "tail between hind legs excuse". No, we don't buy that either.>Let me ask you a question in return? Are you happy with the SB>Relay, SB, AVC and the associated harangue to connect? That>PID/VID you have is just for this purpose to make your online>flying better!! or are you happy as an online flyer that the>community is becoming closed and proprietory by the day!!!No, I am not fully satisfied by SB/AVC but that does not mean that I have to accept TheSunTeam practices. >Carelessness is not equal to maliciousnessAs I said - too lame and too late. If they were "careless" , they would have gone back to the drawing table and ask themselves why people are crying "wolf". They would have offered to help the investigation and then explain why this happened.No. Instead they argued and argued about their software calling back with personal info. They called people liars for saying that and they called these facts "allegations".Sorry. As I see it from here, they were "disappointed" by IVAO and VATSIM refusal to support their venture and then decided to do something about it. What was their end purpose is a matter of "vivid imagination" or "stupid logic" but there are many valid questions still hanging in the air - questions which have never been answered, and frankly, they ceased to be interesting anyway since now it's too late. What they did was not the result of an "honest mistake" of "carelessness". It has "malicious intent" written all over it and if damage hasn't been done yet, that's because several people took the time to analyze what exactly was behind SquawkWin.And that couldn't have happened soon enough.Al

Guest
This topic is now closed to further replies.

Account

Navigation

Search

Search

Configure browser push notifications

Chrome (Android)
  1. Tap the lock icon next to the address bar.
  2. Tap Permissions → Notifications.
  3. Adjust your preference.
Chrome (Desktop)
  1. Click the padlock icon in the address bar.
  2. Select Site settings.
  3. Find Notifications and adjust your preference.