Gentoo Archives: gentoo-security

From: Peter Simons <simons@××××.to>
To: gentoo-security@l.g.o
Subject: [gentoo-security] Re: No, apparently not.
Date: Mon, 08 Nov 2004 02:33:47
Message-Id: 87ekj5qdcf.fsf@peti.cryp.to
In Reply to: Re: [gentoo-security] No, apparently not. by Brian Bilbrey
1 Brian Bilbrey writes:
2
3 > Then, at the user end, after performing an emerge sync,
4 > the process is run again, by portage:
5
6 > export FILENAME=`cat /usr/portage/serial_number`
7 > wget http://www.gentoo.org/$FILENAME
8
9 The process breaks at this point because if someone can
10 redirect your access to a sync mirror, he can redirect your
11 access to the web server, too. So the hash will always match
12 the portage tree because the attacker generated both.
13
14
15 > Let's be useful to the developers here, folks.
16
17 I have posted a concrete proposal that does fix the problem
18 long before this thread spun out of control.
19
20 Peter
21
22
23 --
24 gentoo-security@g.o mailing list