Security Basics mailing list archives

Helix vs. Backtrac: DCFLDD problem


From: Adam Mooz <adam.mooz () gmail com>
Date: Wed, 15 Jul 2009 10:01:15 -0400

Hello List,

I'm hoping someone can verify or explain (or both) what is happening
here.  I've been playing with both Helix and Backtrack 4 Pre.  There
is a discrepency between DCFLDD and MD5sum on Helix but not on
Backtrack.  What I've done is the following:

I created a temporary random file using "cat /dev/urandom > test.txt"
(let that run, get a good 1GB file.)
Then copied it using "dcfldd if=test.txt of=test2.txt hash=md5
hashlog=test2.txt.md5 totalhashformat="#hash#  test2.txt"
conv=sync,noerror"
- The totalhashformat just spits out the hash log in a format MD5SUM
will understand.
Attempted to verify using "md5sum -c test2.txt.md5" which then check
the hash found within the file to the hash it generates (obviously.)

The problem is, on Helix the verification fails but (using the same
input file test.txt) in Backtrack the verification suceeds.  The only
conclusion I can see is that when Helix is/was "revamping" the free
utils to make them proprietary they mangled part of DCFLDD (or one of
it's dependencies.)  I've tried this on multiple computers using the
same source data and get the same results.

Can anyone else verify this or know what is happening?

------------------------------------------------------------------------
Securing Apache Web Server with thawte Digital Certificate
In this guide we examine the importance of Apache-SSL and who needs an SSL certificate.  We look at how SSL works, how 
it benefits your company and how your customers can tell if a site is secure. You will find out how to test, purchase, 
install and use a thawte Digital Certificate on your Apache web server. Throughout, best practices for set-up are 
highlighted to help you ensure efficient ongoing management of your encryption keys and digital certificates.

http://www.dinclinx.com/Redirect.aspx?36;4175;25;1371;0;5;946;e13b6be442f727d1
------------------------------------------------------------------------


Current thread: