LWN.net Logo

Worrying initial conclusion?

Worrying initial conclusion?

Posted Dec 20, 2007 13:37 UTC (Thu) by gnb (subscriber, #5132)
Parent article: The backdooring of SquirrelMail

 The quoted section of the initial announcement is a little worrying: 
compromising the release packages involved effort on someone's part and, 
as a motivation for that effort, introducing an exploitable vulnerability 
is a far, _far_ likelier goal that adding a random bug. So the initial 
position should probably be to assume that whoever made the changes 
intended them to be exploitable and therefore to act as though there 
were a compromise introduced until those changes are fully understood. 
That is, the healthy initial reaction is "what have I missed?" rather 
than "this doesn't seem to do anything".


(Log in to post comments)

Copyright © 2008, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds