Slashdot Mirror


CERT: Sendmail Distribution Contained Trojan Horse

Scoria writes "According to a CERT advisory published this afternoon, the public distribution of Sendmail 8.12.6 contained a trojan horse from September 28 to October 6. For more detailed information, please consult advisory CA-2002-28." This sounds very much like what happened to OpenSSH.

8 of 324 comments (clear)

  1. But that's okay... by Anonymous Coward · · Score: 5, Funny

    As long as you could also get the source to the Trojan, as well... right?

  2. Thank GOD for Microsoft! by eamber · · Score: 5, Funny

    Good thing I use Exchange Server. I've got a tight ship there.

    1. Re:Thank GOD for Microsoft! by Sabalon · · Score: 5, Funny

      Don't forget that according to the earlier article you will now need to pay extra for that tight ship - otherwise you get the submarine with the screen door.

  3. This is a good reason to get windows! by greenskyx · · Score: 4, Funny

    That way when you get your software you know who put the security holes in it. It's all part of trustworthy computing... ;-)

  4. Re:Checksums by Anonymous Coward · · Score: 5, Funny

    Also can't forget about the black hats and chinese/russian/terrorist groups as well.

    Incorrect md5 sums certainly strike terror into my heart.

  5. Re:Only the FTP... by Quixote · · Score: 4, Funny
    I even seem to remember pressed CDs being distributed with trojans.

    Surely these can't be Microsoft CDs!?! According to a KB article at Microsoft.com, "Disks are duplicated on a variety of industrial strength, quality focused systems. Most of these systems are UNIX-based. The UNIX-based duplication systems used in manufacturing are impervious to MS-DOS-based, Windows-based, and Macintosh-based viruses."

  6. Re:LMAO! by Wdomburg · · Score: 4, Funny

    >It is still funny, simply because it is yet
    >another sendmail problem.

    Yeah, and if someone breaks into your house and pees on your carpet, it's yet another carpet problem.

    Matt

  7. Re:Hardly news ... by Trogre · · Score: 5, Funny

    Let's see, a Trojan Horse is basically defined as an undocumented chunk of code hiding inside a program, which does something that you don't know about or understand.

    Not quite.
    A Trojan Horse is defined as a big wooden horse which sat outside the ancient city of Troy, just large enough to happily contain 700 greeks in full battle dress and still leave adequate room for toilet facilities.

    For more information read Homers's Iliad.

    --
    "Nine times out of ten, starting a fire is not the best way to solve the problem." - my wife