Bugtraq mailing list archives

Re: FreeBSD VM gremlin


From: james () APLDIGITAL COM AU (James McParlane)
Date: Mon, 21 Sep 1998 11:33:11 +1000


This message is in MIME format. Since your mail reader does not understand
this format, some or all of this message may not be legible.

------_=_NextPart_001_01BDE4FF.CECAE03C
Content-Type: text/plain;
        charset="iso-8859-1"

Sounds like we all need EIT :)

http://pobox.upenn.edu/~tex/papers/thesis/index.html

-----Original Message-----
From: Charles M. Hannum [mailto:root () IHACK NET]
Sent: Friday, September 18, 1998 9:49 PM
To: BUGTRAQ () NETSPACE ORG
Subject: Re: FreeBSD VM gremlin


You should have md5 checksums of files that you are concerned about,
as timestamps are useless in the face of a good attacker.

Rubbish!  A checksum doesn't tell me that someone hadn't temporarily
replaced the file and has now put the original back.

------_=_NextPart_001_01BDE4FF.CECAE03C
Content-Type: text/html;
        charset="iso-8859-1"
Content-Transfer-Encoding: quoted-printable

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 3.2//EN">

<HTML>
<HEAD>
<META HTTP-EQUIV=3D"Content-Type" CONTENT=3D"text/html; =
charset=3Diso-8859-1">
<META NAME=3D"Generator" CONTENT=3D"MS Exchange Server version =
5.5.2232.0">
<TITLE>RE: FreeBSD VM gremlin</TITLE>
</HEAD>
<BODY>


<FONT SIZE=3D2>Sounds like we all need EIT :) </FONT>
</P>


<FONT SIZE=3D2><A =
HREF=3D"http://pobox.upenn.edu/~tex/papers/thesis/index.html"; =
TARGET=3D"_blank">http://pobox.upenn.edu/~tex/papers/thesis/index.html</=
A></FONT>
</P>


<FONT SIZE=3D2>-----Original Message-----</FONT>
<BR><FONT SIZE=3D2>From: Charles M. Hannum [<A =
HREF=3D"mailto:root () IHACK NET">mailto:root () IHACK NET</A>]</FONT>
<BR><FONT SIZE=3D2>Sent: Friday, September 18, 1998 9:49 PM</FONT>
<BR><FONT SIZE=3D2>To: BUGTRAQ () NETSPACE ORG</FONT>
<BR><FONT SIZE=3D2>Subject: Re: FreeBSD VM gremlin</FONT>
</P>


<FONT SIZE=3D2>> You should have md5 checksums of files that you =
are concerned about,</FONT>
<BR><FONT SIZE=3D2>> as timestamps are useless in the face of a good =
attacker.</FONT>
</P>


<FONT SIZE=3D2>Rubbish!  A checksum doesn't tell me that =
someone hadn't temporarily</FONT>
<BR><FONT SIZE=3D2>replaced the file and has now put the original =
back.</FONT>
</P>

</BODY>
</HTML>

------_=_NextPart_001_01BDE4FF.CECAE03C--



Current thread: