From owner-freebsd-security Thu Aug 1 16:59:49 2002 Delivered-To: freebsd-security@freebsd.org Received: from mx1.FreeBSD.org (mx1.FreeBSD.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id BF31F37B400 for ; Thu, 1 Aug 2002 16:59:47 -0700 (PDT) Received: from russian-caravan.cloud9.net (russian-caravan.cloud9.net [168.100.1.4]) by mx1.FreeBSD.org (Postfix) with ESMTP id 68F1A43E42 for ; Thu, 1 Aug 2002 16:59:47 -0700 (PDT) (envelope-from Hostmaster@Video2Video.Com) Received: from earl-grey.cloud9.net (earl-grey.cloud9.net [168.100.1.1]) by russian-caravan.cloud9.net (Postfix) with ESMTP id 1A0A928E32; Thu, 1 Aug 2002 19:59:18 -0400 (EDT) Date: Thu, 1 Aug 2002 19:59:08 -0400 (EDT) From: Peter Leftwich X-X-Sender: To: Artur Lindgren Cc: FreeBSD Security LIST Subject: Re: Trojan located in latest openssh tar files In-Reply-To: <20020801193739.3b40bcb8.yid@softhome.net> Message-ID: <20020801195813.Q12126-100000@earl-grey.cloud9.net> Organization: Video2Video Services - http://Www.Video2Video.Com MIME-Version: 1.0 Content-Type: TEXT/PLAIN; charset=US-ASCII Sender: owner-freebsd-security@FreeBSD.ORG Precedence: bulk List-ID: List-Archive: (Web Archive) List-Help: (List Instructions) List-Subscribe: List-Unsubscribe: X-Loop: FreeBSD.org On Thu, 1 Aug 2002, Joshua Lee wrote: > On Thu, 1 Aug 2002 14:11:24 +0200 Artur Lindgren wrote: > > I noticed that openssh-3.4p has a trojan horse (available from ftp://ftp.openbsd.org/pub/OpenBSD/OpenSSH/portable/openssh-3.4p1.tar.gz and some of the mirrors. > Is this a problem for someone who makes world with FreeBSD and gets OpenSSH from the source tree or only for people who get OpenSSH via ports? Can you be more specific about your discovery please? -- Peter Leftwich President & Founder Video2Video Services Box 13692, La Jolla, CA, 92039 USA +1-413-403-9555 To Unsubscribe: send mail to majordomo@FreeBSD.org with "unsubscribe freebsd-security" in the body of the message