Another source distribution trojan
[Posted November 13, 2002 by corbet]
Here we go again... the source distribution of a popular application has
been compromised by a trojan horse. This time around, the affected
application is tcpdump, which was compromised on November 11 and
remained available for download for two days. As with other trojans, this
one opens up a connection to a remote host, which can then execute shell
commands. The fact that tcpdump was compromised allowed an additional
twist, however: tcpdump will not show traffic to and from the hostile
remote system.
For more information, see this CERT
advisory.
(
Log in to post comments)