Fake Red Hat security update
Posted Oct 25, 2004 16:08 UTC (Mon) by
JoeBuck (subscriber, #2330)
Parent article:
Fake Red Hat security update
This shows that it was a very wise decision to add digital signatures to RPMs, and to have the rpm program verify those signatures before installation. If it were not for that, these guys could have packaged their trojan as an RPM, and with suitable trickery they might even have misled people into thinking they were getting the RPM off of a Red Hat site.
But an RPM that is not signed with a key that is already loaded into the
rpm database will not install.
(
Log in to post comments)