]> jfr.im git - irc.git/blob - software/!RELEASES/ircservices/achurch.org/services/lists/ircservices/2002/002955.html
RELEASE -> !RELEASE
[irc.git] / software / !RELEASES / ircservices / achurch.org / services / lists / ircservices / 2002 / 002955.html
1 <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 3.2//EN">
2 <HTML>
3 <HEAD>
4 <TITLE> [IRCServices] Trojan warning and MD5 checksums
5 </TITLE>
6 <LINK REL="Index" HREF="index.html" >
7 <LINK REL="made" HREF="mailto:ircservices%40ircservices.za.net?Subject=%5BIRCServices%5D%20Trojan%20warning%20and%20MD5%20checksums&In-Reply-To=">
8 <META NAME="robots" CONTENT="index,nofollow">
9 <META http-equiv="Content-Type" content="text/html; charset=us-ascii">
10 <LINK REL="Previous" HREF="002954.html">
11 <LINK REL="Next" HREF="002956.html">
12 </HEAD>
13 <BODY BGCOLOR="#ffffff">
14 <H1>[IRCServices] Trojan warning and MD5 checksums</H1>
15 <B>Andrew Church</B>
16 <A HREF="mailto:ircservices%40ircservices.za.net?Subject=%5BIRCServices%5D%20Trojan%20warning%20and%20MD5%20checksums&In-Reply-To="
17 TITLE="[IRCServices] Trojan warning and MD5 checksums">achurch at achurch.org
18 </A><BR>
19 <I>Fri May 31 19:40:01 PDT 2002</I>
20 <P><UL>
21 <LI>Previous message: <A HREF="002954.html">[IRCServices] Another Feature Suggestion
22 </A></li>
23 <LI>Next message: <A HREF="002956.html">[IRCServices] Mailing list
24 </A></li>
25 <LI> <B>Messages sorted by:</B>
26 <a href="date.html#2955">[ date ]</a>
27 <a href="thread.html#2955">[ thread ]</a>
28 <a href="subject.html#2955">[ subject ]</a>
29 <a href="author.html#2955">[ author ]</a>
30 </LI>
31 </UL>
32 <HR>
33 <!--beginarticle-->
34 <PRE> Recently, two open-source programs (the &quot;irssi&quot; IRC client and another
35 program called fragroute) have been trojaned by someone breaking into the
36 distribution site and modifying the &quot;configure&quot; script of each program to
37 spawn a shell accessible over the network. I am not aware of any case in
38 which a Services distribution/mirror site has been broken into, but to be
39 safe, I will from now on release MD5 digests of each distribution file on
40 the appropriate mailing list; at least for the near future, it would be
41 advisable to compare these to the MD5 digests of the files you download to
42 ensure they have not been modified (or simply corrupted in transfer). Most
43 Linux distributions have a program called &quot;md5&quot; or &quot;md5sum&quot; which will
44 print the MD5 digest of a given file, and can be used for such comparisons.
45 (Note that the MD5 digests will not be stored on the FTP sites, for the
46 obvious reason that if an attacker could change the distribution files
47 themselves, they could just as easily change the checksum file as well.)
48
49 For reference, the MD5 digests of the current stable and beta
50 distribution files are as follows:
51
52 MD5 (ircservices-4.5.40.diff.gz) = 605d8c0f92b37f4509f65de8e56b446e
53 MD5 (ircservices-4.5.40.tar.gz) = 77020902db4845c928e103861f534df2
54 MD5 (beta/ircservices-5.0pre0-1.i386.rpm) = 1a2982000f28c41a7dd09300e3107543
55 MD5 (beta/ircservices-5.0pre0.tar.gz) = c6239c42d029a64da4207bf22e3b0b7e
56 MD5 (beta/ircservices_5.0pre0-1_i386.deb) = b2f8fefbfee495b72afa6b70fc88424e
57
58 --Andrew Church
59 <A HREF="http://www.ircservices.za.net/mailman/listinfo/ircservices">achurch at achurch.org</A>
60 <A HREF="http://achurch.org/">http://achurch.org/</A>
61
62 </PRE>
63
64 <!--endarticle-->
65 <HR>
66 <P><UL>
67 <!--threads-->
68 <LI>Previous message: <A HREF="002954.html">[IRCServices] Another Feature Suggestion
69 </A></li>
70 <LI>Next message: <A HREF="002956.html">[IRCServices] Mailing list
71 </A></li>
72 <LI> <B>Messages sorted by:</B>
73 <a href="date.html#2955">[ date ]</a>
74 <a href="thread.html#2955">[ thread ]</a>
75 <a href="subject.html#2955">[ subject ]</a>
76 <a href="author.html#2955">[ author ]</a>
77 </LI>
78 </UL>
79
80 </body></html>