Re: OpenBSD 4.1 Torrents

Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]
From: Justin Smith
Date: Saturday, May 5, 2007 - 3:43 am

> Just out of curiosity...

 > Is it logical to use an OS for the intense focus on security and
 > correctness, yet download the binaries from a random person on a mailing
 > list instead of any official source with reasonable file integrity
 > checking process in place?

From:

http://toolbar.netcraft.com/site_report?url=ftp.openbsd.org

Site http://ftp.openbsd.org

Reverse DNS	openbsd.sunsite.ualberta.ca

Netblock Owner	IP address	OS	Web Server	Last changed

University of Alberta 1030 General Services Building Edmonton
CA	129.128.5.191	Solaris	Apache/1.3.34 Unix PHP/4.4.2
mod_perl/1.27	17-Apr-2007

What a security!!

FYI:

"Trojaned version of OpenSSH package has been found to reside on
ftp.openbsd.org's server."

http://www.mavetju.org/unix/openssh-trojan.php
http://www.openssh.org/txt/trojan.adv

Are you remember?

-- 
JS
Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]

Messages in current thread:
Re: OpenBSD 4.1 Torrents, Justin Smith, (Sat May 5, 3:43 am)
Re: OpenBSD 4.1 Torrents, Clint M. Sand, (Sat May 5, 5:57 pm)