{"id":1424,"date":"2016-09-17T07:22:02","date_gmt":"2016-09-17T05:22:02","guid":{"rendered":"http:\/\/borncity.com\/win\/?p=1424"},"modified":"2020-12-13T06:43:00","modified_gmt":"2020-12-13T05:43:00","slug":"heidoc-net-and-windows-und-office-iso-download-tool-an-update","status":"publish","type":"post","link":"https:\/\/borncity.com\/win\/2016\/09\/17\/heidoc-net-and-windows-und-office-iso-download-tool-an-update\/","title":{"rendered":"heidoc.net and &lsquo;Windows und Office ISO Download Tool&rsquo; &ndash; an update"},"content":{"rendered":"<p><img loading=\"lazy\" decoding=\"async\" style=\"float: left; margin: 0px 10px 0px 0px; display: inline\" src=\"http:\/\/www.borncity.com\/blog\/wp-content\/uploads\/2013\/03\/winb.jpg\" width=\"58\" align=\"left\" height=\"58\">[<a href=\"http:\/\/www.borncity.com\/blog\/2016\/09\/17\/update-zu-heidoc-net-und-windows-und-office-iso-download-tool\/\" target=\"_blank\" rel=\"noopener\">German<\/a>]Yesterday I reported, that the site <em>heidoc.net<\/em> and the 'Windows und Office ISO Download Tool' is no longer available (see my blog post <a href=\"https:\/\/borncity.com\/win\/2016\/09\/16\/microsoft-ends-techbench-program-axes-windows-iso-download-tool-heidoc-net-is-dead\/\">Microsoft ends Techbench program; axes Windows ISO Download Tool &amp; heidoc.net is dead?<\/a>). But that was a false alarm \u2013 the site and the tool is back to life. In this blog post I will uncover a few details what has happens. <\/p>\n<p><!--more--><\/p>\n<p><img loading=\"lazy\" decoding=\"async\" alt=\"\" src=\"https:\/\/ssl-vg03.met.vgwort.de\/na\/e9c9cd243978447ab26d26cc41500488\" width=\"1\" height=\"1\">Sometimes things are different from what the first view suggests \u2013 and sometimes a third and fourth detailed view is needed. <\/p>\n<h3>The history<\/h3>\n<p>I'm using a plugin within my blog to detect broken links within the blog posts. Yesterday I found a long list of broken links, and many are pointing to <em>heidoc.net<\/em>. After I inspected the links reported, I found out, that not only the whole Joomla contend was gone. Also <em>heidoc.net <\/em>pointed to a cambodian auction platform.<\/p>\n<p><img decoding=\"async\" title=\"heidoc.net\" alt=\"heidoc.net\" src=\"https:\/\/web.archive.org\/web\/20191012044242\/http:\/\/t74.imgup.net\/heidoc-netb087.jpg\"><\/p>\n<p>A short check of \"Windows and Office ISO Downloader\" gave me the following error message. <\/p>\n<p><img decoding=\"async\" src=\"https:\/\/web.archive.org\/web\/20191012044241\/http:\/\/e05.imgup.net\/heidoc-net078f.jpg\"><\/p>\n<p>Then things went even worser: During investigating the case, I found posts in German forums, that the latest Downloads of the tool was quoted from several third party antivirus scanner als \"trojan infected\". And a few hours later, Google Chrome blocked <em>heidoc.net <\/em>with a warning, that the certificate was invalid. <\/p>\n<p>I was aware, that the owner of <em>heidoc.net<\/em>, Jan Krohn, has moved from Germany to Cambodia. So my conclusion was: Either Jan has given up his activities in ISO downloader and dedicated his site to another user \u2013 or even bad things happens (a site was infected or hijacked). <\/p>\n<h3>Jan Krohn left a comment to explain the incident<\/h3>\n<p>Later on, I received reports, that <em>heidoc.net <\/em>was back to life and also the \"Windows and Office ISO Downloader\" works again. Then Jan Krohn (the owner of <em>heidoc.net<\/em>) left a <a href=\"http:\/\/www.borncity.com\/blog\/2016\/09\/16\/aus-fr-heidoc-net-und-das-iso-download-tool\/#comment-35598\" target=\"_blank\" rel=\"noopener\">Comment in my German blog<\/a>, explaining the issue. Here is a free translated version<\/p>\n<blockquote>\n<p>Sorry, my fault\u2026 during installing my SSL certificates on my two domains I reversed the certificates. \u2026 Version 3.20 is coming soon, including integrated download lists, in case heidoc.net is unavailable.<\/p>\n<\/blockquote>\n<p>Here I will thank Jan for his insight. And sorry to my blog readers for the false alarm. It was also partially my fault, I have had information that I could verify (the not reachable heidoc.net site, the blocked certificate and the broken Download tool). And I know that Jan has moved to Cambodia and that Microsoft's Techbench program site was redirected to a Windows 10 download site. My fault: I mixed these information to a inaccurate image.  <\/p>\n<p>Yes, the tool and the site wasn't availabe. And No, Jan Krohn did not intend to axes the tool and his site.  <\/p>\n<h3>Wait, there is a bit more to tell \u2026<\/h3>\n<p>Ok, Jan explained some thing, and my assumptions are false at the end of the day. Job done? After I left a comment under a <a href=\"https:\/\/www.youtube.com\/watch?v=wsQ5cFI12jE&amp;google_comment_id=z13yh1xaxkjcifupi04cfj2ahnfpzfao1uw0k\" target=\"_blank\" rel=\"noopener\">MajorGeeks YouTube-video<\/a>, I received a \"our post smells like spam. The tool works just fine. I just tested and downloaded.\" \u2013 ok, I understand their position \u2013 but it's a bit too simple, isn't it. So I decided to uncover a few additional things (I haven't read that in many \"nice\" US blogs introducing this tool). <\/p>\n<p><strong>What's happended (probably) <\/strong><\/p>\n<ul>\n<li>Jan Krohn runs two sites with separate domains, <em>heidoc.net <\/em>and an auction site in Pnom Penh.\n<li>He switched the sites to <em>https<\/em> and was in need to associate a SSL certificate.\n<li>From what I've seen during the day, first he reversed the (MX) records, so <em>heidoc.net <\/em>pointed for hours with a valid certificate to the auction site. Of course, all urls pointing to his heidoc.net Joomla sites was broken (that was what a plugin reports within my blog).\n<li>Then he tried to fix things, and for some times the SSL certificates was reversed, so the site was blocked in Google Chrome (due to certificate errors).\n<li>The malfunction of the 'Windows und Office ISO Download Tool' was a \"following error\". The tool needs access to a list of Techbench download links, hostet on <em>heidoc.net<\/em> server. If heidoc.net is down, the ISO downloader stalls.&nbsp; <\/li>\n<\/ul>\n<p>Although I would quote the ISO downloader as \"helpful\", this case shows \"the devil is in the detail\". So here are a few additional thoughts. A few days ago I read a Google announcement, that Google Chrome will mark http sites as unsecure \u2013 forcing users to upgrade their web servers to https support. The incident shown above is a nice example, what could be happen, if things are required, without weighting the details \u2013 but that's only a side note. <\/p>\n<h3><strong>Implications for ISO-Downloaders<\/strong><\/h3>\n<p>Jan Krohn announced within his comment a Version 3.20 of his tool that comes with the Techbench Link lists. So the tool doesn't depend on a running <em>heidoc.net<\/em> server. But lets have a&nbsp; closer look at this decision from a programmers view. <\/p>\n<ul>\n<li>The current implementation download the Techbench Link lists to the Microsoft Download-Server from heidoc.net. This gives Jan the possibility to amend the list on his server (single source).&nbsp;\n<li>But, if somebody is able to hack the Joomla server and alter the list, it would be possible to force the ISO downloader to download fake ISO images with malware \u2013 it's a security risk. <\/li>\n<\/ul>\n<p>An let me note: This risk is available, although the heidoc.net server communication is secured with <em>https<\/em>! If the server is compromised, https doesn't helps. <\/p>\n<p>Now Jan Krohn plans to release Version 3.20 of his 'Windows and Office ISO Download Tool' that ships the Techbench-Download-Link list. The tool doesn't need the heidoc.net server anymore. But: If something is changing within the download link list, a new version of the tool is mandatory. A possible solution: Jan implements a dynamic update of the local list from his server. <\/p>\n<blockquote>\n<p>I mentioned several reports in German forums, that the latest download of the ISO downloader was flagged from third party AV tools as \"Trojan infected\". I never have had such a version, so I guess, it was also false alarms. So I can's say more. But it shows, how complex things can be. <\/p>\n<\/blockquote>\n<p><img decoding=\"async\" title=\"TechBenchDump\" alt=\"TechBenchDump\" src=\"https:\/\/web.archive.org\/web\/20191012044241\/http:\/\/s22.imgup.net\/TechDumpGi2152.jpg\"> <\/p>\n<p>I've mentioned in my blog post <a href=\"https:\/\/borncity.com\/win\/2016\/09\/16\/microsoft-ends-techbench-program-axes-windows-iso-download-tool-heidoc-net-is-dead\/\">Microsoft ends Techbench program; axes Windows ISO Download Tool &amp; heidoc.net is dead?<\/a> another solution. Experienced users should vitit the site <a href=\"https:\/\/web.archive.org\/web\/20161224014754\/https:\/\/gist.github.com\/mkuba50\/27c909501cbc2a4f169be4b4075a66ff\">TechBench dump<\/a> at GitHub. This site delivers the direct download links to Microsoft's download servers (so no tool is necessary). But I like to give here also a clear warning: Github communication is secured by <em>https<\/em>, but users need to trust that Github isn't compromised. If the Github download link list is compromised, it's possible to point to fake ISO downloads. And if the Github server stalls, downloads are not possible. <\/p>\n<p>Just a tip: To avoid compromised download, you can check the download links before initiating a download. <\/p>\n<p><img decoding=\"async\" src=\"https:\/\/web.archive.org\/web\/20191012044242\/http:\/\/s13.imgup.net\/Github4536.jpg\"><\/p>\n<p>Just point with the cursor to the download link shown within the Github site, allows you to verify via the browser's status bar that the link points to a Microsoft download server. <\/p>\n<blockquote>\n<p>If Jan Krohn reads this, I would recommend to implement a similar mechanism within his ISO-Downloader Version 3.20. <\/p>\n<\/blockquote>\n<h3>Final Thoughs<\/h3>\n<p>Well, I wrote a lot about this case \u2013 and sorry for my wrong assumption in my previous post. But: This case can be an example to have a closer look at things and don't trust such tools.&nbsp; <\/p>\n<p><strong>Similar articles:<\/strong><strong><br \/><\/strong><a href=\"https:\/\/borncity.com\/win\/2016\/06\/25\/microsoft-windows-and-office-iso-download-tool\/\">Microsoft Windows and Office ISO download tool<\/a><br \/><a href=\"https:\/\/borncity.com\/win\/2016\/08\/03\/microsoft-july-2016-security-release-iso-image\/\">Microsoft July 2016 Security Release ISO Image<\/a><br \/><a href=\"https:\/\/borncity.com\/win\/2016\/09\/16\/microsoft-ends-techbench-program-axes-windows-iso-download-tool-heidoc-net-is-dead\/\">Microsoft ends Techbench program; axes Windows ISO Download Tool &amp; heidoc.net is dead?<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>[German]Yesterday I reported, that the site heidoc.net and the 'Windows und Office ISO Download Tool' is no longer available (see my blog post Microsoft ends Techbench program; axes Windows ISO Download Tool &amp; heidoc.net is dead?). But that was a &hellip; <a href=\"https:\/\/borncity.com\/win\/2016\/09\/17\/heidoc-net-and-windows-und-office-iso-download-tool-an-update\/\">Continue reading <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[11,2],"tags":[412,410,411],"class_list":["post-1424","post","type-post","status-publish","format-standard","hentry","category-office","category-windows","tag-a","tag-heidoc-net","tag-iso-download-tool"],"_links":{"self":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/posts\/1424","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/comments?post=1424"}],"version-history":[{"count":0,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/posts\/1424\/revisions"}],"wp:attachment":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/media?parent=1424"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/categories?post=1424"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/tags?post=1424"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}