Download Sites Hacked, Source Code Backdoored
Brian McWilliams, SecurityFocus 2002-06-03

The popular open-source security tool Fragroute is bugged in plain sight by unknown hackers, who may have struck before.

Comments Mode:
Download Sites Hacked, Source Code Backdoored 2002-06-04
Coldman (6 replies)
Download Sites Hacked, Source Code Backdoored 2002-06-04
doxavg (1 replies)
Download Sites Hacked, Source Code Backdoored 2002-06-07
Anonymous (2 replies)
Download Sites Hacked, Source Code Backdoored 2002-06-12
Robert Pitt
If the kids who broke into the site had the knowledge to alter the irc clients code, then it's not a great leap of the imagination to suppose they would have little problem defeating such an obvious protection method either. More than anything this would simply make the site admins feel (falsely) secure. As another guy on here wrote, authenticity verification data of that sort should be kept on read-only media. Furthermore, it should be run manually and not automatically since if I had hacked into a site, one of the first things I would do is turn off that crontab job running tripwire while I trojaned the binary (if the admin was silly enough to leave it on their HD) or trojaned the kernel to render it ineffective if they had it on read-only media. Finally, having another (locked down) machine performing verification via a network link to the files might be beneficial as the kid(s) can't fool that machine without making it send the original files over the network, possibly defeating the purpose.

[ reply ]

Link to this comment: http://www.securityfocus.com/comments/articles/462/13009#13009
well.. 2002-06-04
frozen chocolate jesus
Download Sites Hacked, Source Code Backdoored 2002-06-04
cras (1 replies)
Download Sites Hacked, Source Code Backdoored 2002-06-05
Anonymous (1 replies)
Download Sites Hacked, Source Code Backdoored 2002-06-07
Chris Berry <compjma (at) hotmail (dot) com [email concealed]> (1 replies)
open vrs closed... 2002-06-05
Anonymous
You're wrong. 2002-06-14
twoforty
Not only one 2002-06-07
notstarh


 

Privacy Statement
Copyright 2010, SecurityFocus