Free Republic
Browse · Search
News/Activism
Topics · Post Article

Per Slapdash. I predict great fun from this, so none of that reasoned discourse nonsense from you people ;)
1 posted on 09/21/2005 7:57:23 AM PDT by general_re
[ Post Reply | Private Reply | View Replies ]


To: ShadowAce

FYI.


2 posted on 09/21/2005 8:00:26 AM PDT by general_re ("Frantic orthodoxy is never rooted in faith, but in doubt." - Reinhold Niebuhr)
[ Post Reply | Private Reply | To 1 | View Replies ]

To: general_re
Right after the Linux manifesivos stuck foot in mouth over Symantec's study!
3 posted on 09/21/2005 8:00:27 AM PDT by Dan Nunn
[ Post Reply | Private Reply | To 1 | View Replies ]

To: general_re

A tripwire daemon would catch the changed size of the executables, right?


4 posted on 09/21/2005 8:01:30 AM PDT by proxy_user
[ Post Reply | Private Reply | To 1 | View Replies ]

To: general_re

CP/M - The only way to go.


5 posted on 09/21/2005 8:03:56 AM PDT by Tennessee_Bob ("Nac Mac Feegle! The Wee Free Men! Nae king! Nae quin! Nae laird! We willna be fooled again!")
[ Post Reply | Private Reply | To 1 | View Replies ]

To: general_re

This is as I predicted here on FR last year (and got thoroughly trashed as being a complete ignoramus). I love Firefox. I'm using it right now, but Mozilla used to benefit from its relative anonymity. Why go after it when you could screw up the day of millions of Windows' users.

Well, boys and girls, success has now made Mozilla a target....


6 posted on 09/21/2005 8:04:27 AM PDT by freebilly (Go USF Baseball!)
[ Post Reply | Private Reply | To 1 | View Replies ]

To: general_re

Thanks for alerting us.


15 posted on 09/21/2005 8:30:44 AM PDT by lilylangtree
[ Post Reply | Private Reply | To 1 | View Replies ]

To: general_re
Yet another example of why you should have an up to date antivirus solution, and scan EVERYTHING you download, without exception.

Another important step is get the package signatures (MD5, SHA, PGP, etc) from a different service and compare to the signature of the downloaded package. Some folks download the source and compile to produce just the signatures as a public service.

I don't see this mentioned anywhere on the mozilla page, btw. However it's mentioned in the developer side. Other open source binaries (e.g. Apache, OpenOffice, etc) usually are distributed with signatures.

17 posted on 09/21/2005 8:34:07 AM PDT by no-s
[ Post Reply | Private Reply | To 1 | View Replies ]

To: general_re

Sometimes, it's important to dig a little deeper. In this case, it was not mozilla.org that had the infected binaries, but rather a Mozilla fan site in Korea. This should not need repeating, but it's probably not safe to donwload programs from arbitrary servers on the Internet.

You can continue to safely download files from mozilla.org


19 posted on 09/21/2005 8:41:55 AM PDT by duckhead
[ Post Reply | Private Reply | To 1 | View Replies ]

To: general_re
"This virus searches for executable ELF files in the current and /bin directories and infects them. When infecting files, it writes itself to the middle of the file, at the end of a section of code, which pushes the other sections lower down. It also contains a backdoor, which downloads scripts from another site, and executes them, using a standard shell."

Maybe on Linspire - a Linux for newbies that logs users on as root (like WinderzXP). Not on my Debian box.

21 posted on 09/21/2005 8:50:25 AM PDT by PokeyJoe (There are 10 kinds of people in the world. Those who understand binary, and those that don't.)
[ Post Reply | Private Reply | To 1 | View Replies ]

To: general_re
Not the first time the host servers from an open source vendor have been rooted. Remember these?

GNU Project's FTP Servers Hacked

Gentoo Linux Server Hacked

Debain Servers Hacked

Things like this happen when you let just anyone view your source code.

26 posted on 09/21/2005 9:52:07 AM PDT by Golden Eagle
[ Post Reply | Private Reply | To 1 | View Replies ]

To: general_re

Seems to be a recurring problems for these Mozilla guys.

http://www.mozillazine.org/talkback.html?article=6771

Nice blimp.


27 posted on 09/21/2005 9:56:45 AM PDT by Golden Eagle
[ Post Reply | Private Reply | To 1 | View Replies ]

Free Republic
Browse · Search
News/Activism
Topics · Post Article


FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson