As detailed in
this CERT advisory, the
sendmail source distribution on ftp.sendmail.org was replaced by a version
containing a trojan horse. The modified code stayed on the server from
September 28 through October 6. The trojan was invoked during
the build process; it would fire off a process that would listen for
commands on port 6667. If you downloaded and installed sendmail during
that time period, you need to take a serious look at the integrity of your
systems.
Free software is supposed to be more secure because the source can be
examined for this sort of thing. Yet this particular bit of malware
managed to stay on a high-profile server for over a week. When you
consider that, for example, the Interbase back door went undiscovered for
over a year, one week does not seem all that bad. But one week is plenty
of time to compromise a great many systems.
What is truly surprising is that we have not seen more of this sort of
problem. Trojanized source distributions are scary; a compromised binary
package is truly terrifying. There will be more - and worse -
episodes of this nature in the future.
Of course, we have the tools to defend against most of these attacks. If
you put up software for others to download, you should sign it with a
cryptographic key. If you download software, you should check that
signature. As long as the signing keys are handled carefully
(i.e. not stored on the FTP server!), this bit of hygene will detect
almost all tampering attacks. Without such checks, administrators are
placing a great deal of trust in the security of every system they download
software from.
Comments (2 posted)
The LinuxSecurity.com "Linux Security Week" newsletter for October 7
is available.
Full Story (comments: none)
News.com has
a report from Whitfield Diffie's talk at the RSA conference.
"
Diffie also said that security cannot be delegated, nor can a user rely on one company for security. 'Openness is essential for trust,' he said, referring to open-source code, as well as compatibility.
"
Comments (none posted)
Michael D. Bauer
talks about Linux security issues on O'Reilly.
"
I don't presume to know in any definitive way whether Linux is more or less securable than other Unix variants. What I do know is this: Linux is useful, stable, and securable enough to warrant the time and effort required to "harden" it against Internet threats. This article explains some of the reasons I believe it's both possible and worthwhile to secure Linux for use as an Internet server platform.
"
Comments (none posted)
The 19th annual Chaos Computer Club Congress will be held in Berlin on
December 27 to 29. The Call for Papers has gone out; no deadline
for submissions has been specified. "
So, do you dare to speak in
front of people who might have downloaded your
script from your computer in advance and spotted all the logical
errors?
"
Full Story (comments: none)
The 2003 Computers, Freedom, and Privacy conference will be held
April 1 to 4 in New York. The Call for Papers is out, with a
deadline of November 15.
Full Story (comments: none)