Date: Sun, 28 Jan 2007 14:13:51 -0600 From: Paul Schmehl <pauls@utdallas.edu> To: Pekka Riikonen <priikone@iki.fi> Cc: "Freebsd Ports: Archivers" <ports@freebsd.org>, security@silcnet.org, aquatique-ports@rambler.ru Subject: Re: Problem with devel/silc-toolkit Message-ID: <103D5836493CBF0EACA17AE1@paul-schmehls-powerbook59.local> In-Reply-To: <Pine.NEB.4.64.0701280942560.23771@otaku.Xtrmntr.org> References: <3B27E5D772A78D81D72D9420@paul-schmehls-powerbook59.local> <20070128014441.GA76439@atarininja.org> <D2F9DABD9A545B74551F4D18@paul-schmehls-powerbook59.local> <20070128024514.GA79142@atarininja.org> <2A54A37FBF8B6E7EE4DEAA5F@paul-schmehls-powerbook59.local> <20070128033157.GB79646@atarininja.org> <A2FDF255F8D7771162FF6E97@paul-schmehls-powerbook59.local> <Pine.NEB.4.64.0701280942560.23771@otaku.Xtrmntr.org>
next in thread | previous in thread | raw e-mail | index | archive | help
--==========CD3AFD0E86C586C0B559========== Content-Type: text/plain; charset=us-ascii; format=flowed Content-Transfer-Encoding: quoted-printable Content-Disposition: inline --On January 28, 2007 9:55:42 AM +0100 Pekka Riikonen <priikone@iki.fi>=20 wrote: > : > Thanks for letting us know about these issues, but we have not updated > the files at silcnet.org since they were put up there. They were last > modified Dec 19 2005. I suspect you had some local problem or download > problem or some mirror was corrupted. I also verified the files this > morning and the md5sums are as follows: > Well now you have me even more concerned. I downloaded the file directly=20 from silcnet.org using both the port and ftp, and I also downloaded the=20 file on my Mac here at home using ftp to pull the file both from the http=20 and the ftp download sites. In all four cases, the md5sum and the sha256=20 sum did not match the file that was downloaded. Furthermore, the size of=20 the file was a meg less than it was supposed to be. Then, while I was downloading copies from some of the mirrors to check=20 them, the file from silcnet.org suddenly matched the md5sum and the size=20 of the legitimate file. While it's entirely possible that *both* my=20 FreeBSD box *and* my Mac were somehow screwed up, it's hard to believe=20 that *multiple* downloads on both boxes would arrive at the same results=20 and then suddenly they would change, yet nothing changed at the=20 distribution site. It's certainly odd enough to warrant a thorough=20 investigation, I would think. There was obviously a problem somewhere, but I'm not convinced it was on=20 both of my boxes and nowhere else. Paul Schmehl (pauls@utdallas.edu) Senior Information Security Analyst The University of Texas at Dallas http://www.utdallas.edu/ir/security/ --==========CD3AFD0E86C586C0B559==========--
Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?103D5836493CBF0EACA17AE1>