Re: Troff dangerous.

From: Groovy Pants Gus (gusat_private)
Date: Mon Jul 26 1999 - 22:03:13 PDT

  • Next message: Trevor Schroeder: "Re: (How) Does AntiSniff do what is claimed?"

    At 01:27 PM 7/25/99 -0700, you wrote:
    >On Sun, 25 Jul 1999 17:29:56 +0600
    > CyberPsychotic <mlistsat_private> wrote:
    >
    
    {snip}
    
    >
    >The trick is that it can get you if you as a system administrator download
    >some open source program from the Internet, and build and install that
    >program; such activity often happens as "root", so a couple of scenarios
    >are possible:
    >
    >	(1) Root installs the malicious roff source unknowingly.
    >
    >	(2) During the process of building/installing the program, groff
    >	    is invoked as root to create a pre-formatted version of
    >	    the manual page (a "cat page"), at which point the trojan
    >	    horse does it dirty work.
    >
    >        -- Jason R. Thorpe <thorpejat_private>
    >
    
    Just some idle thoughts, if a system had already been compromised, a
    backdoor could be put in a man page.. admin thinks he's secure.. admin
    needs to refer to man pages.. man pages insert trojan and email hacker..
    or does tripwire, etc know to check for stuff like that? (and will it
    after all this fuss on the issue has died down? :)
    
    -- Groove On - http://sb7.yoonix.net/~gus/ (might be down, blame admin :)
    



    This archive was generated by hypermail 2b30 : Fri Apr 13 2001 - 14:53:54 PDT