Study: Attacks on package managers
Posted Jul 15, 2008 11:17 UTC (Tue) by
Zenith (subscriber, #24899)
In reply to:
Study: Attacks on package managers by afalko
Parent article:
Study: Attacks on package managers
Quoting rgmoore further up in the discussion:
Someone on Slashdot pointed out a much nastier potential attack. The process is simple:
1. Set up a mirror.
2. Wait for the distro you're mirroring to send out a security update for a package with a remotely exploitable hole.
3. Root the box of everybody who starts to download the updated package.
The mirror can look completely legitimate, because it just passively harvests the IDs of vulnerable computers. You probably want to pass off the job of rooting vulnerable computers to a separate botnet to keep your mirror looking squeaky clean.
So yes, a sort of loophole, but not one you can do much about I would think, besides from the whole "trusted mirrors only" scheme mentioned here in the discussion.
(
Log in to post comments)