Vulnerability Development mailing list archives

Re: Re: ssh trojaned


From: wozz () 0xdeadbeef org
Date: Fri, 2 Aug 2002 11:20:08 -0700


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Of course, verifying checksums does you no good if the checksums have been replaced along with the binary.  Be sure to 
aquire your checksums from some other, presumably safe, location.

On Thu, 1 Aug 2002 22:41:39 +0200 (CEST), Eirik Seim <default () stengt net> wrote:


Oh, and the guys that inserted the trojan might easily had access to more
on the same ftp site, and subsequently also its mirrors.  If you don't
usually verify checksums, now is a great time to start doing so.


- Eirik
--
New and exciting signature!




-----BEGIN PGP SIGNATURE-----
Version: Hush 2.1
Note: This signature can be verified at https://www.hushtools.com

wlsEARECABsFAj1KzbEUHHdvenpAMHhkZWFkYmVlZi5vcmcACgkQ1vK8vFo3sjzZEQCf
YpqiXaafmDfMuhErWoaJ/u86csgAoLvBK8uxMoIDpfZdfOwBrwdnRRYD
=EoUt
-----END PGP SIGNATURE-----


Current thread: