On Wed, 9 Oct 2002, Richard Lightman wrote:
> * Jason Gurtz <[email protected]> [2002-10-09 07:32]:
> >
> >
> > > This forked process allows the intruder to open a shell
> > > running in the context of the user who built the
> > > Sendmail software.
> >
> > Ahh, another warning I see to be sure one is not building their software
> > as root
> >
> Or, another reason to check the signature. A reasonable way to
> check the keys are valid for high profile software is to wait a
> few days. If the key is wrong, you can expect a news of it to hit
> the security sites.
*ding-ding-ding-ding-ding*
We have a winner!
While it might be useful to not run untrusted installation scripts as
root, if the new package was made by applying patches to the old, and
you've eyeballed those patches, it becomes another matter entirely.
On the other hand, six out of the last seven of these types of incidents
have involved the software being changed in a manner such that any attempt
to verify the tarball's integrity would _immediately_ show something was
not in order.
The real thing to be worried about here is that it's beginning to look
like it takes the general populace an average of three to five days before
even ONE of the people downloading things checks some sort of
signature--versus the thousand or so people who've also downloaded it but
never bothered to test it for spring freshness.
--
Unsubscribe: send email to [email protected]
and put 'unsubscribe lfs-security' in the subject header of the message
lmpx.com only provides a reader for public news (NNTP) servers. It is not
affiliated with the servers or forums shown here and is not responsible for
the content of articles, which is written by their respective authors.