Re: Am I downloading what I think I am (was Re: I doubt that this affects FreeBSD, but FYI
From: Dragos Ruiu (dr@kyx.net)
Date: 10/09/02
- Next message: Chris McCluskey: "VPN Solutions for Win 2K/XP -> FreeBSD (Possible FAQ entry)"
- Previous message: Nicholas Esborn: "Re: Am I downloading what I think I am (was Re: I doubt that this affects FreeBSD, but FYI"
- In reply to: Claus Assmann: "Re: Am I downloading what I think I am (was Re: I doubt that this affects FreeBSD, but FYI"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
From: Dragos Ruiu <dr@kyx.net> To: security@FreeBSD.ORG, Claus Assmann <freebsd+security@esmtp.org> Date: Wed, 9 Oct 2002 13:47:37 +0000
On October 9, 2002 08:16 pm, Claus Assmann wrote:
> On Wed, Oct 09, 2002, Mike Tancsa wrote:
> > Sorry, I should have been more clear. I was speaking more to
> > the general issue of a user downloading both the binary and checksum from
> > the same source as is / was the case with ftp.sendmail.org.
>
> For sendmail the MD5 sums are in the PGP signed announcements. If
> you can verify the PGP signature of the announcements and you can
> "trust" the PGP key, then you're as safe as if you do the same check
> for the PGP signature of the tar file itself.
And as long as the announcements that went out were the ones that left
and the checksums mailed were good.
If that server is back to trusted now, another authoritative method would be
code diffs. (find -type f -exec diff -u \{\} ../oldsendmail/\{\} )
-- dr@kyx.net pgp: http://dragos.com/kyxpgp Advance CanSecWest/03 registration available: http://cansecwest.com "The question of whether computers can think is like the question of whether submarines can swim." --Edsger Wybe Dijkstra 1930-2002 To Unsubscribe: send mail to majordomo@FreeBSD.org with "unsubscribe freebsd-security" in the body of the message
- Next message: Chris McCluskey: "VPN Solutions for Win 2K/XP -> FreeBSD (Possible FAQ entry)"
- Previous message: Nicholas Esborn: "Re: Am I downloading what I think I am (was Re: I doubt that this affects FreeBSD, but FYI"
- In reply to: Claus Assmann: "Re: Am I downloading what I think I am (was Re: I doubt that this affects FreeBSD, but FYI"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]