[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: KDE phoning home



On Thu, Sep 04, 2025 at 01:14:19PM -0000, Rob Brewer wrote:
Over the last few days my desktop has been attempting to connect to
77.235.60.43 port 443 (about 350 attempts a day) which have been dropped
at my firewall as the IP is included in AS60781 (Leaseweb) which has been
listed in a local blacklist as a source of spam.

A google search on this address would appear to show that this address is
crash-reports.kde.org although this cannot be confirmed with whois.

(not sure what did you want to confirm with whois, but you could confirm it with host)

Investigating my logs would seem to show that the connection attempts seem
to be associated with drkonqi-sentry-postman.service - Submitting pending
crash events, although I am not aware of any crash events occurring on
this computer over the last few days.

Check ~/.cache/drkonqi/sentry-envelopes

analysing what information drkonki is trying to send and could be a
security breach.

Check ~/.cache/drkonqi/sentry-envelopes

--
WBR, wRAR

Attachment: signature.asc
Description: PGP signature


Reply to: