Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs
Download Sites Hacked, Source Code Backdoored
Brian McWilliams, SecurityFocus 2002-06-03

The popular open-source security tool Fragroute is bugged in plain sight by unknown hackers, who may have struck before.

Comments Mode:
Download Sites Hacked, Source Code Backdoored 2002-06-04
Coldman (6 replies)
well.. 2002-06-04
frozen chocolate jesus
The argument for security in opensource software is based on the fact that bugs are found, disclosed, and fixed quickly..... but the argument doesn't really apply here, this isn't a bug, it's a backdoor in the code, and it could have happened to anything, opensource or not.

Your suggestion that all sources you download should be audited is a great idea, however rediculous it may be. Are you seriously suggesting that people should audit xfree86 before compiling it? kde? any kernel?

That's where signature checking comes in. You can't force people to do it, but it's certainly preferable to auditing large amounts of code. The fact that most people don't check can't be helped. I can't force people to shower either, but that doesn't mean it's not a Good Thing (tm)

[ reply ]

Link to this comment: http://www.securityfocus.com/comments/articles/462/12890#12890
Download Sites Hacked, Source Code Backdoored 2002-06-04
cras (1 replies)
Download Sites Hacked, Source Code Backdoored 2002-06-05
Anonymous (1 replies)
Download Sites Hacked, Source Code Backdoored 2002-06-07
Chris Berry <compjma (at) hotmail (dot) com [email concealed]> (1 replies)
open vrs closed... 2002-06-05
Anonymous
You're wrong. 2002-06-14
twoforty
Not only one 2002-06-07
notstarh







 

Privacy Statement
Copyright 2009, SecurityFocus