Trojan in TCP Dump

From: Matthew Bukaty (MatthewB@4GUARDIAN.COM)
Date: 11/13/02

  • Next message: 3APA3A: "LOM: Multiple vulnerabilities in Macromedia Flash ActiveX"

    Date:         Wed, 13 Nov 2002 14:08:14 -0500
    From: Matthew Bukaty <MatthewB@4GUARDIAN.COM>
    To: NTBUGTRAQ@LISTSERV.NTBUGTRAQ.COM
    
    

    Slashdot.org is reporting the following:

    Trojan Found in libpcap and tcpdump
    Posted by michael on Wednesday November 13, @08:24AM
    from the when-your-packet-sniffer-won't dept.
    msolnik writes "Members of The Houston Linux Users Group discovered that the
    newest sources of libpcap and tcpdump available from tcpdump.org were
    contaminated with trojan code. HLUG has notified the maintainers of
    tcpdump.org. See our reports here or here."

    ( Read More... | 255 of 387 comments )

    The Link to the article can be found here: http://hlug.fscker.com/

    ______________________________________________
    Matthew T. Bukaty
    MIS Director
    Guardian International
    http://www.guardianinternational.com
    (954) 926 - 1800 Ext. 333

    _____________________________________________________
    Technology Advisory Committee Chairman
    Network Security Lecturer
    Broward Community College



    Relevant Pages

    • CERT Advisory CA-2002-30 Trojan Horse tcpdump and libpcap Distributions
      ... code distributions of the libpcap and tcpdump packages were modified ... have been modified by an intruder and contain a Trojan horse. ... The following distributions were modified to include the malicious ...
      (Cert)
    • Pdox runtime 9 trojan (not)
      ... Some of my customers have lately been reporting to me that a file I've been ... distributing with a paradox program is infected with a trojan. ... as being infected with TROJ_CIH.DAM by the latest definitions in Trend Micro ...
      (comp.databases.paradox)
    • Re: Virus?
      ... Hey - thanks for reporting back! ... It's educational for the folks reading, ... > Trojan Tooncom.1 ...
      (microsoft.public.scripting.virus.discussion)
    • Kernel 2.6.13 breaks libpcap (and tcpdump).
      ... Kernel 2.6.13. ... Breaks libpcap. ... tcpdump ... send the line "unsubscribe linux-kernel" in ...
      (Linux-Kernel)
    • Re: I would like to tcpdump and get all the packets...
      ... >>additional hacks)? ... > I mean libpcap, which also tcpdump uses, if I´m not mistaken. ...
      (freebsd-net)