OT-Re: CERT Advisory CA-2002-28 Trojan Horse Sendmail Distribution
Ken Dyke <[email protected]>
| Newsgroups | gmane.linux.lfs.security |
|---|---|
| Message-ID | <1034276929.12883.23.camel@FatBoy> |
On Thu, 2002-10-10 at 12:21, Sam Halliday wrote: > On 10 Oct 2002 12:10:03 -0600 Ken Dyke <[email protected]> > wrote: > > I know how. And now it is in the mail archives if it wasn't before. > > Files can also be checked with > > md5sum foo.bar > > then check the hash against the published md5 signature. The md5 > > checksum for gnupg can be found on http://www.gnupg.org/download.html > > but this is insecure... if the ftp site has been hacked, chances are > that the md5sum has been also... only trust md5sums which have been > signed. You are in a non-terminating loop as regards gnupg. The gnupg.org http server and the ftp server are different machines (I believe). They are definitely not the same as the mirrors. IIRC trojan packages are usually injected into a mirror. Anyway, as regards gnupg the Gordian Knot must be sliced. Taking this leap and recognizing it for what it is, gnupg can then be used to verify other packages. If at some point in the future, it is revealed that the gnupg package was in fact compromised, one gets to start over from the beginning. Another option for cutting this Knot is to audit the gnupg package yourself. :-) -- I think, therefore, ken_i_m Chief Gadgeteer, Elegant Innovations -- Unsubscribe: send email to [email protected] and put 'unsubscribe lfs-security' in the subject header of the message