Re: tar/security best practice (was Re: RE: Is FreeBSD's tar susceptible to this?)

From: f.johan.beisser (jan@caustic.org)
Date: 10/02/02


Date: Tue, 1 Oct 2002 19:12:11 -0700 (PDT)
From: "f.johan.beisser" <jan@caustic.org>
To: Brian Behlendorf <brian@hyperreal.org>

On Tue, 1 Oct 2002, Brian Behlendorf wrote:

> So, fix the ports system then to include a step whereby someone has to
> pause the installation process to review the output of tar before allowing
> it to proceed.

if you're installing a port, i would tend to assume it's A) from the
FreeBSD ports tree, and B) checked out, and using an md5 hash (already in
the tree) that's separate/updated by the maintainer. in this case, the
port maintainer is directly responsible for the port. of course, you have
to trust your port maintainer to not be out to cause harm.

trust does have to begin somewhere, after all.

-------/ f. johan beisser /--------------------------------------+
  http://caustic.org/~jan jan@caustic.org
    "John Ashcroft is really just the reanimated corpse
         of J. Edgar Hoover." -- Tim Triche

To Unsubscribe: send mail to majordomo@FreeBSD.org
with "unsubscribe freebsd-security" in the body of the message



Relevant Pages

  • Re: How do I create a USB printer port manually
    ... The Lexmark printer drivers are known to do some strange things, so I suggest "cleaning" your print spooler environment, then doing the installation from scratch. ... I happen to have a Canon IP 8500 which installed without a hitch on my XP SP2 desktop following the instructions from Canon. ... I'm not familiar with the Dell computers specifically, but we had some computers at work where things like mice would only work properly when connected directly to the laptop as opposed to through a "port replicator" or "docking cradle". ...
    (microsoft.public.win2000.printing)
  • Re: I am happy with XP:s integreted firewall!
    ... You CAN attack any open port if something is listening, ... CPU upto 100% and keep it there for as long as the cracker kept sending ... > wide world (I have made just one installation of windows XP and I allmost ...
    (comp.security.firewalls)
  • Re: MassStorageDrivers via BootCD?
    ... port non-whql-signed device drivers ... n't extend the existing installation partition ... ternet information services documentation ... ternet information services administration ...
    (microsoft.public.de.german.win2000.setup)
  • Re: SerialPort for Active perl 5.6.1
    ... Summary after successful installation ... port, at least with the available examples coming with SerialPort. ... e.g. to install the pure Perl module ...
    (comp.lang.perl.modules)
  • Re: Filering usb mouse data
    ... > I have successfully installed moufiltr on PS/2 port by simply change ... Installation inf for the Device that needs flitering adapter. ... Install the port driver and mouclass from msmouse.inf ...
    (microsoft.public.development.device.drivers)

Quantcast