Re: CERT Advisory CA-2002-28 Trojan Horse Sendmail Distribution
Richard Lightman <[email protected]>
| Newsgroups | gmane.linux.lfs.security |
|---|---|
| Message-ID | <[email protected]> |
* Jason Gurtz <[email protected]> [2002-10-09 07:32]: > > > > This forked process allows the intruder to open a shell > > running in the context of the user who built the > > Sendmail software. > > Ahh, another warning I see to be sure one is not building their software > as root > Or, another reason to check the signature. A reasonable way to check the keys are valid for high profile software is to wait a few days. If the key is wrong, you can expect a news of it to hit the security sites. Richard -- Unsubscribe: send email to [email protected] and put 'unsubscribe lfs-security' in the subject header of the message