Security Basics mailing list archives

Re: sendmail trojan


From: "Stephane Nasdrovisky" <stephane.nasdrovisky () uniway be>
Date: Fri, 18 Oct 2002 10:10:25 +0200


Haven't you ever heard of code review ?  It's part of any decent software
development process.

Alexandros Papadopoulos wrote:


Frankly, even if the trojan was enclosed in <blink></blink> statements, in
80,000 lines of code it would be lost. It's not feasible for one single coder
to proofread everything he/she compiles. You have to implicitly trust the
coder/maintainer/distributor, I see no other way.



Current thread: