[LUGOS-SEC] Fwd: openssh-3.4p1.tar.gz distribution recently trojaned

Tadej Kirinchich - Kiri_ kiri at siol.net
Mon Aug 5 14:38:39 CEST 2002


ce pa nimas vez .tar.gz pa gres v dir (ce mas odpakiran source na disku) openssh-3.4p1/openbsd-compat , pa nardis cat Makefile.in |grep bf-test.c ....in ce ti najde kasno vrstico z tem, ves da mas tistga z trojancem


Mon, 5 Aug 2002 14:08:02 +0200 je Matej Zerovnik - LeVaK <levak at planetq.org> napisal:

> Kolikor jaz vem je bil hacknen samo ftp.openbsd.org in èe si od tam pobral 
> openssh je mo¾no da si pobral tistega z trojancam... Preveri MD5 sourca.. To 
> je vse kar ti lahko recem:)
> 
> This is the md5 checksum of the openssh-3.4p1.tar.gz in the FreeBSD
> ports system:
>     MD5 (openssh-3.4p1.tar.gz) = 459c1d0262e939d6432f193c7a4ba8a8
> 
> This is the md5 checksum of the trojaned openssh-3.4p1.tar.gz:
>     MD5 (openssh-3.4p1.tar.gz) = 3ac9bc346d736b4a51d676faa2a08a57
> 
> LeVaK


-- 
farewell
--
lp tk
--------------------------------------------------
E-mail: kiri at sobotainfo.com | kiri at siol.net
Informacijsko Sredisce Pomurja: www.sobotainfo.com
IRCNET: Kiri_ (#ms, #sip, #lugos...)
GSM: +386-31-380836
--------------------------------------------------

Ker zivljenje NI keks!



More information about the lugos-sec mailing list