Gentoo Logo
Gentoo Spaceship




Note: Due to technical difficulties, the Archives are currently not up to date. GMANE provides an alternative service for most mailing lists.
c.f. bug 424647
List Archive: gentoo-security
Navigation:
Lists: gentoo-security: < Prev By Thread Next > < Prev By Date Next >
Headers:
To: gentoo-security@g.o
From: Peter Simons <simons@...>
Subject: Is anybody else worried about this? (was: Trojan for Gentoo, part 2)
Date: 07 Nov 2004 14:14:28 +0100
Fellow Gentoo'ers,

I have to say that I am shocked by Alexander's posting. Once
more I am forced to recognize that there is a difference
between knowing that an exploit is "theoretically possible"
and _seeing_ the actual exploit implemented in under 50
lines of code.

Having said that, I am even more shocked by the fact that
this problem has been long known! As a user who doesn't like
the idea of giving up control of his machines to random
people on the Internet, I would kindly request a statement
from the Gentoo developers about this. Specifically:

 (1) Do you agree that this is a problem?

 (2) Are there plans for getting it fixed?

 (3) Is there any estimate how long this will take?

I have read some of the material Alexander hyper-linked to
and, frankly, most of it is outright frightening.


 > PPPS: I really appreciate all the very good work on
 > hardened gcc, selinux-profiles and so on, but for me,
 > this all seems useless as long as the base is compromised
 > that easy and the user has no practical way (e.g. hashs)
 > to check what he gets on his machine with a 'sync'.

I wholeheartedly agree.

Peter


--
gentoo-security@g.o mailing list

Replies:
Re: Is anybody else worried about this? (was: Trojan for Gentoo, part 2)
-- Kurt Lieber
Re: Is anybody else worried about this?
-- Marc Ballarin
References:
Trojan for Gentoo, part 2
-- Alexander Holler
Navigation:
Lists: gentoo-security: < Prev By Thread Next > < Prev By Date Next >
Previous by thread:
Re: How to authenticate the portage tree
Next by thread:
Re: Is anybody else worried about this?
Previous by date:
Re: help blocking automated ssh scanning attack script
Next by date:
Re: help blocking automated ssh scanning attack script


Updated Jun 17, 2009

Summary: Archive of the gentoo-security mailing list.

Donate to support our development efforts.

Copyright 2001-2013 Gentoo Foundation, Inc. Questions, Comments? Contact us.