Re: CERT Advisory CA-2002-28 Trojan Horse Sendmail Distribution

Richard Lightman <[email protected]>
Newsgroups gmane.linux.lfs.security
Message-ID <[email protected]>
* Jason Gurtz <[email protected]> [2002-10-09 07:32]:
> 
> 
> > This forked  process allows  the  intruder  to open a shell
> > running in the context  of  the  user  who  built  the
> > Sendmail software.
> 
> Ahh, another warning I see to be sure one is not building their software
> as root
> 
Or, another reason to check the signature. A reasonable way to
check the keys are valid for high profile software is to wait a
few days. If the key is wrong, you can expect a news of it to hit
the security sites.

Richard

-- 
Unsubscribe: send email to [email protected]
and put 'unsubscribe lfs-security' in the subject header of the message
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.