From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: X-Spam-Checker-Version: SpamAssassin 4.0.0 (2022-12-14) on finch.gentoo.org X-Spam-Level: X-Spam-Status: No, score=-0.5 required=5.0 tests=DMARC_QUAR, FREEMAIL_FORGED_FROMDOMAIN,FREEMAIL_FROM,HEADER_FROM_DIFFERENT_DOMAINS, MAILING_LIST_MULTI,NICE_REPLY_A,RDNS_DYNAMIC autolearn=unavailable autolearn_force=no version=4.0.0 Received: from VikingPC.home (dsl-213-023-054-149.arcor-ip.net [213.23.54.149]) by chiba.3jane.net (Postfix) with ESMTP id 0C9FEAC37C for ; Thu, 1 Aug 2002 05:10:46 -0500 (CDT) Received: by VikingPC.home (Postfix, from userid 1000) id EAE091B401E; Thu, 1 Aug 2002 12:10:11 +0200 (CEST) Date: Thu, 1 Aug 2002 12:10:11 +0200 From: Eric Noack To: gentoo-dev@gentoo.org Subject: Re: [gentoo-dev] possible trojan in openssh-3.4p1 Message-Id: <20020801121011.198cfa7f.eric.noack@gmx.de> In-Reply-To: <1028193533.12255.17.camel@uranus.u235.eyep.net> References: <20020801103714.A26100@capsi.com> <1028193533.12255.17.camel@uranus.u235.eyep.net> X-Mailer: Sylpheed version 0.8.1claws (GTK+ 1.2.10; ) Mime-Version: 1.0 Content-Type: text/plain; charset=US-ASCII Content-Transfer-Encoding: 7bit Sender: gentoo-dev-admin@gentoo.org Errors-To: gentoo-dev-admin@gentoo.org X-BeenThere: gentoo-dev@gentoo.org X-Mailman-Version: 2.0.6 Precedence: bulk List-Help: List-Post: List-Subscribe: , List-Id: Gentoo Linux developer list List-Unsubscribe: , List-Archive: X-Archives-Salt: e6ff5749-463c-4a03-bc6d-9ab299af3e08 X-Archives-Hash: dd051055393cd9bd5d75e2c27fb30b1b Am 01 Aug 2002 12:18:53 +0300 schrieb Vitaly Kushneriuk : > It's indeed looks like a trojan. It doesn't send you'r etc/passwd tho. > It connects to the 203.62.158.32[web.snsonline.net.] port 6667[irc] > and opens shell session on that connection, so that whoever is in > control there will be able to execute arbitraty commands on your system > with you'r current privileges. especialy dangerouus if you compile as > root. im not so big into the code, but the file @ ibiblio.org seems to be ok ftp://ibiblio.org/pub/Linux/distributions/gentoo/distfiles/openssh-3.4p1.tar.gz -rw-r--r-- 1 raven users 837668 08-01 12:06 openssh-3.4p1.tar.gz.ibiblio.org -rw-r--r-- 1 raven users 840574 08-01 11:46 openssh-3.4p1.tar.gz.dangerous_from.ftp.openbsd.org -rw-r--r-- 1 root root 837668 08-01 11:35 openssh-3.4p1.tar.gz.ok see the different sizes? interesting. that says enough. however the file mentionen (openbsd-compat/bf-test.c) doesnt exist in the ibiblio version so i hope this one is clean. such thing must never happen! Corvus Corax