Re: Ports are insecure?

From: Alex Kiesel (alex.kiesel@document-root.de)
Date: 08/27/02


Date: Tue, 27 Aug 2002 22:30:16 +0200
From: Alex Kiesel <alex.kiesel@document-root.de>
To: Erick Mechler <emechler@techometer.net>

On Aug 27, 2002, Erick Mechler wrote:
> Not just anybody can contribute to a FreeBSD port entry; the commit still
> has to be done by an authorized committer. However, it's true that just
> about anybody's software package can become a port, so if you just blindly
> start installing ports, you might, on rare occasions, install a piece of
> software that's been trojaned (take the recent OpenSSH trojan for example).

As the ports collection has a checksum for every file that is needed, it
should not be a big problem to avoid installing trojanized software.

IIRC you could not install OpenSSH without ignoring checksum alerts.

Cheers,
Alex

-- 
Alex Kiesel                                     PGP Key: 0x09F4FA11
To Unsubscribe: send mail to majordomo@FreeBSD.org
with "unsubscribe freebsd-security" in the body of the message


Relevant Pages

  • Re: installation of toolbox and native ARM in port 2: difficulties and solution
    ... Installing the ARM toolbox and ARM ... always failed in port 2, ...
    (comp.sys.hp48)
  • installation of toolbox and native ARM in port 2: difficulties and solution
    ... Installing the ARM toolbox and ARM ... Repeatedly installing/removing toolbox 3.12 and other ARM libraries ... always failed in port 2, ...
    (comp.sys.hp48)
  • Re: Disabling Serial Ballpoint Mouse when GPS connected
    ... common occurance when this GPS is installed? ... > the 'found new hardware' Wizard requesting the driver for the new mouse. ... > connected to the serial port and to see if it's a mouse. ... > installing devices, but this would mean that the USB to Serial drivers ...
    (microsoft.public.win32.programmer.kernel)
  • Re: Cant Install ISA!
    ... it gets as far as installing the MSDE and then fails with: ... Charles - do I really need port 25 open? ... I don't believe Exchange is relaying through SMTP (unless ... I'm not sure I fully understand what firewall is actually running. ...
    (microsoft.public.windows.server.sbs)
  • Re: Cant Install ISA!
    ... it gets as far as installing the MSDE and then fails with: ... Charles - do I really need port 25 open? ... I don't believe Exchange is relaying through SMTP (unless ... I'm not sure I fully understand what firewall is actually running. ...
    (microsoft.public.windows.server.sbs)