Re: chfn, date, chsh INFECTED according to chkrootkit

From: Thordur Ivar B. (thib_at_mi.is)
Date: 08/18/04

  • Next message: Matt Piechota: "Re: chfn, date, chsh INFECTED according to chkrootkit"
    Date: Wed, 18 Aug 2004 16:23:55 +0000
    To: freebsd-security@freebsd.org
    
    

    On Wed, 18 Aug 2004 16:49:49 +0200
    Nicolas Rachinsky <list@rachinsky.de> wrote:

    > * "Thordur Ivar B." <thib@mi.is> [2004-08-18 14:25 +0000]:
    > > But still, you can only be sure if you trust you CVS checkout.
    >
    > And your compiler and other tools used to build everything.
    >
    > http://www.acm.org/classics/sep95/
    >
    > Nicolas
    > _______________________________________________
    > freebsd-security@freebsd.org mailing list
    > http://lists.freebsd.org/mailman/listinfo/freebsd-security
    > To unsubscribe, send any mail to "freebsd-security-unsubscribe@freebsd.org"
    >
    >

    Yes ofcourse you will need to trust your own toolchain and compiler (I keep
    "trusted" binarys on CD to use in cases like this. (And for post-mortem
    inspection.)

    -- 
    Kv, thib[att]mi{dot}is
    A man can do as he will, but not will as he will.
    		-- Arthur Schopenhauer
    _______________________________________________
    freebsd-security@freebsd.org mailing list
    http://lists.freebsd.org/mailman/listinfo/freebsd-security
    To unsubscribe, send any mail to "freebsd-security-unsubscribe@freebsd.org"
    

  • Next message: Matt Piechota: "Re: chfn, date, chsh INFECTED according to chkrootkit"

    Relevant Pages

    • Re: chfn, date, chsh INFECTED according to chkrootkit
      ... you can only be sure if you trust you CVS checkout. ... And your compiler and other tools used to build everything. ... Nicolas ...
      (FreeBSD-Security)
    • Re: Encrypting/Decrypting Password from a Config File
      ... >> That assumes you trust the compiler. ... even if each of the individual components behave exactly ... And there's still the issue of trusting your own senses. ...
      (comp.lang.java.programmer)
    • Re: Encrypting/Decrypting Password from a Config File
      ... US code breakers broke a one time pad because they found it ... That assumes you trust the compiler. ... So your best bet is to build a read-only USB key from scratch, ...
      (comp.lang.java.programmer)
    • Re: Is argv array modifiable ?
      ... It is up to programmers to educate themselves on what that language is. ... things that you might think are correct, and might work on your compiler this week, might fail abysmally when it actually matters to you. ... trust assemblers, text editors or the OS by that reasoning. ... Still I do find these conversations fascinating, and I always enjoy the cranky attitude found on usenet! ...
      (comp.lang.c)
    • Re: [Lit.] Buffer overruns
      ... > (trust the compiler) and all kinds of cans of worms pop up. ... And you talk like someone who decides how many bugs he'll tolerate ... > development project; your expertise and experience has been ...
      (sci.crypt)