Re[2]: [Full-Disclosure] KDE was hacked

From: 3APA3A (3APA3A_at_SECURITY.NNOV.RU)
Date: 05/08/04

  • Next message: Feher Tamas: "[Full-Disclosure] Victory day - Sasser surrenders"
    To: Seth Alan Woolley <seth@tautology.org>
    Date: Sat, 8 May 2004 15:22:33 +0400
    
    

    Dear Seth Alan Woolley,

    --Saturday, May 8, 2004, 2:14:49 AM, you wrote to full-disclosure@lists.netsys.com:

    SAW> Anybody using a CVS build of KDE is taking an inherent risk for such
    SAW> things as this. Anybody using an official release would of course have
    SAW> a plethora of people reviewing each commit. It only took them 1.5 hours
    SAW> according to the Russian article to spot the code comments. I'd say the
    SAW> KDE team passed with flying colors.

    It's always possible to insert "backdoor" into code in a way it will
    probably never be caught during audit, if code is rather large and is
    not perfectly styled. It may be a call to wrong function in a case of
    some race conditions or another "unexpected" situation - things almost
    impossible to catch for a person who didn't wrote this code from
    beginning. It's true for both open source and commercial software, but
    commercial developers at least have signed contracts. Any exploitable
    bug found in software could actually be a backdoor. It's a question of
    trust.

    -- 
    ~/ZARAZA
    ÝÍÈÀÊàì - ïî ìîðäå!  (Ëåì)
    _______________________________________________
    Full-Disclosure - We believe in it.
    Charter: http://lists.netsys.com/full-disclosure-charter.html
    

  • Next message: Feher Tamas: "[Full-Disclosure] Victory day - Sasser surrenders"

    Relevant Pages

    • Re: [Full-Disclosure] KDE was hacked
      ... Anybody using a CVS build of KDE is taking an inherent risk for such ... KDE team passed with flying colors. ... code audit to both free and proprietary code bases to see if such things ... Seth Alan Woolley, ...
      (Full-Disclosure)
    • Re: [kde] kcontrol kcmshell "privacy"
      ... Most KDE config files are ... Sorry but I don't use a commercial software to "click a box" ... KDE development, which is what I was thinking of when I said they ... Profitez des connaissances, des opinions et des expériences des internautes sur Yahoo! ...
      (KDE)

  • Quantcast