LWN.net Logo

Advertisement

E-Commerce & credit card processing - the Open Source way!

Advertise here

Trojan horse in OpenSSH 3.4p1 source distribution

Trojan horse in OpenSSH 3.4p1 source distribution

Posted Aug 1, 2002 15:07 UTC (Thu) by craighagan (guest, #3045)
Parent article: Trojan horse in OpenSSH 3.4p1 source distribution

This appears to be a FreeBSD ports thing. I build from
sources downloaded from the openssh website within 24 hours
of the release. I've double-checked said sources and
do *not* see either the Makefile.in modification
nor the bf-test.c source via find.

I recommend other folks check their sources so that
either the ports origin -- or a hack at openssh's distribution
point can be confirmed.


(Log in to post comments)

Trojan horse in OpenSSH 3.4p1 source distribution

Posted Aug 1, 2002 15:08 UTC (Thu) by craighagan (guest, #3045) [Link]

silly me. i forgot that -ports ftp's the software upon build.

Trojan horse in OpenSSH 3.4p1 source distribution

Posted Aug 1, 2002 16:22 UTC (Thu) by erat (guest, #21) [Link]

I built 3.4p1 last night from a tarball downloaded from openssh.com. No trojan found, and the checksum matched the "good" checksum from the security alert.

Copyright © 2008, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds