Re: librsync and rsync vulnerability to maliciously crafted data. was Re: MD4 checksum_seed

Martin Pool <[email protected]> Thu, 8 Apr 2004 12:36:53 +1000
Newsgroups gmane.network.librsync.devel
Message-ID <[email protected]>
--S5HS5MvDw4DmbRmb
Content-Type: text/plain; charset=us-ascii
Content-Disposition: inline
Content-Transfer-Encoding: quoted-printable

On  5 Apr 2004, Donovan Baarda <[email protected]> wrote:

> librsync needs a whole file checksum. Without it, it silently fails for
> case 1), 3), and 4).

Yes, a whole-file checksum should be used with it.  Presumably
something stronger than md4 like SHA-1.

I think the only question is whether this should be done internally in
librsync, or as a separate process.  I can see arguments either way. =20

In some cases you might prefer to actually store an signed signature
using something like GPG.
=20
> librsync could benefit from a random checksum_seed. It would need to be
> included in the signature. Without it librsync is vulnerable to cases 1)
> and 3).

Random with respect to what?  I think it would be nice if repeatedly
summing identicaly files gave identical signatures.  Maybe it can vary
depending on only the input data...

--=20
Martin=20

--S5HS5MvDw4DmbRmb
Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: Digital signature
Content-Disposition: inline

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.4 (GNU/Linux)

iD8DBQFAdLrFPGPKP6Cz6IsRAiEyAKDMD4H+Ao2kZY/ap8VbWHdPodChoQCdHYP7
yhqvYiuRXdhWOWDwC5Gtonk=
=c/AU
-----END PGP SIGNATURE-----

--S5HS5MvDw4DmbRmb--


-------------------------------------------------------
This SF.Net email is sponsored by: IBM Linux Tutorials
Free Linux tutorial presented by Daniel Robbins, President and CEO of
GenToo technologies. Learn everything from fundamentals to system
administration.http://ads.osdn.com/?ad_id=1470&alloc_id=3638&op=click