Re: securing a unix system - suggestions on checking for intrusions
Volker Kuhlmann <[email protected]>
| Newsgroups | gmane.org.user-groups.linux.new-zealand.general |
|---|---|
| Message-ID | <[email protected]> |
On Thu 06 Oct 2011 17:04:48 NZDT +1300, Jaco wrote: > FYI - if the repo's poisoned, you're borked anyway: > http://www.theregister.co.uk/2011/07/05/ftp_backdoor_shenanigans That's just nonsense. It depends on whether the package was signed with a secure key. If so, you're fine. I remember the time at about 1997 when downloads cost $5/MB (uni, 3x that in town) from offshore but nothing onshore, and I could fetch distro packages from any odd ftp server dodgy or not, it didn't matter. At that time deb hadn't even heard of package signing, or surely hadn't done anything about it. Volker -- Volker Kuhlmann is list0570 with the domain in header. http://volker.dnsalias.net/ Please do not CC list postings to me. _______________________________________________ NZLUG mailing list [email protected] http://www.linux.net.nz/cgi-bin/mailman/listinfo/nzlug