Nmap Security Scanner
*Intro
*Ref Guide
*Install Guide
*Download
*Changelog
*Book
*Docs
Security Lists
*Nmap Hackers
*Nmap Dev
*Bugtraq
*Full Disclosure
*Pen Test
*Basics
*More
Security Tools
*Pass crackers
*Sniffers
*Vuln Scanners
*Web scanners
*Wireless
*Exploitation
*Packet crafters
*More
Site News
Site Search:
Exploit World
Advertising
About/Contact
Credits
Sponsors:
edgeos



Vulnerability Development: Re: ssh trojaned

Re: ssh trojaned

From: <loki__at_softhome.net>
Date: Mon, 5 Aug 2002 17:51:41 +0200

Hi,

On Mon, Aug 05, 2002 at 09:02:38AM -0500, Nick Lange wrote:
> From: "Nick Lange" <nicklange_at_wi.rr.com>
> To: <vuln-dev_at_securityfocus.com>
> Subject: Re: Re: ssh trojaned
> Date: Mon, 5 Aug 2002 09:02:38 -0500
> X-Mailer: Microsoft Outlook Express 5.50.4807.1700
            ^^^^^^^^^^^^^^^^^^^^^^^^^
            Warning: You are using software from Microsoft.

> or perhaps, if I am mirror A have a watchdog script compare my md5 sum to
> every other md5 sum accross the mirrors, and take some action should the
> ratio of unmatching MD5's falls below a certain percentage...

that would not work because a smart attackor would serve the correct
file and hash to the watchdog scripts, iss.com, and so on and
serve the trojaned file to presumedly unsuspecting victims only.
iirc, the trojaned version of epic was served to specific ip ranges
only.

--loki
Received on Aug 05 2002

[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]
edgeos