Gentoo Logo
Gentoo Spaceship




Note: Due to technical difficulties, the Archives are currently not up to date. GMANE provides an alternative service for most mailing lists.
c.f. bug 424647
List Archive: gentoo-security
Navigation:
Lists: gentoo-security: < Prev By Thread Next > < Prev By Date Next >
Headers:
To: gentoo-security@g.o
From: Hans-Werner Hilse <hilse@...>
Subject: Re: Let's blow the whistle
Date: Mon, 8 Nov 2004 15:00:59 +0100
Hello,

On 08 Nov 2004 14:47:15 +0100 you wrote:

> I will publish step-by-step instructions which explain in
> great detail how to ...
> 
>  (1) set up a fake sync mirror,
> 
>  (2) set up a transparent proxy for rsyncd connections that
>      are routed through your machine,
> 
>  (3) configure your BIND daemon to pretend it had
>      authoritative information for the gentoo.org zone that
>      refers to your mirror rather than the real one, and
> 
>  (4) what to patch in /usr/portage/eclass/eutils.eclass to
>      install appropriate exploit code on the user's machine
>      once emerge is used for the next time.

Err... I think this description alone should do it, no need to waste
your time writing the n-th description of how to set up a transparent
proxy, setting up BIND and so on... You could write an ebuild
"hacked-up-rsync-mirror" which does this all, so that all of us
can do some testing :-)

But i doubt that you really manage to hack up my BIND, place a
transparent proxy in my connection to the net or convince me to use your
fake mirror. But go on, play... Don't complain here if you're the one
being laughed at on that mentioned mailing list...

HWH

--
gentoo-security@g.o mailing list

Replies:
Re: Let's blow the whistle
-- Paul de Vrieze
Re: Let's blow the whistle
-- Aiko Barz
Re: Let's blow the whistle
-- Bart
Re: Let's blow the whistle
-- Peter Simons
References:
Let's blow the whistle
-- Peter Simons
Navigation:
Lists: gentoo-security: < Prev By Thread Next > < Prev By Date Next >
Previous by thread:
Let's blow the whistle
Next by thread:
Re: Let's blow the whistle
Previous by date:
Let's blow the whistle
Next by date:
Re: Let's blow the whistle


Updated Jun 17, 2009

Summary: Archive of the gentoo-security mailing list.

Donate to support our development efforts.

Copyright 2001-2013 Gentoo Foundation, Inc. Questions, Comments? Contact us.