Re: CERT Advisory CA-2002-28 Trojan Horse Sendmail Distribution

[email protected]
Newsgroups gmane.linux.lfs.security
Message-ID <[email protected]>
On Wed, 9 Oct 2002, Richard Lightman wrote:

> * Jason Gurtz <[email protected]> [2002-10-09 07:32]:
> >
> >
> > > This forked  process allows  the  intruder  to open a shell
> > > running in the context  of  the  user  who  built  the
> > > Sendmail software.
> >
> > Ahh, another warning I see to be sure one is not building their software
> > as root
> >
> Or, another reason to check the signature. A reasonable way to
> check the keys are valid for high profile software is to wait a
> few days. If the key is wrong, you can expect a news of it to hit
> the security sites.

*ding-ding-ding-ding-ding*

We have a winner!

While it might be useful to not run untrusted installation scripts as
root, if the new package was made by applying patches to the old, and
you've eyeballed those patches, it becomes another matter entirely.

On the other hand, six out of the last seven of these types of incidents
have involved the software being changed in a manner such that any attempt
to verify the tarball's integrity would _immediately_ show something was
not in order.

The real thing to be worried about here is that it's beginning to look
like it takes the general populace an average of three to five days before
even ONE of the people downloading things checks some sort of
signature--versus the thousand or so people who've also downloaded it but
never bothered to test it for spring freshness.

-- 
Unsubscribe: send email to [email protected]
and put 'unsubscribe lfs-security' in the subject header of the message
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.