GENERAL WARNING

Steve Simmons scs at lokkur.dexter.mi.us
Fri Sep 28 09:56:30 AEST 1990


cedman at lynx.ps.uci.edu (Carl Edman) writes:
> Now, really: It is very easy to change particularily a program like
> a shell to f.e. put the name of a non-backtraceable account into the
> .rhosts file and then send mail to it to inform the hacker that
> he has just gotten a new account. Maybe even a su account ?

demon at ibmpcug.co.uk (Cliff Stanford) replies:
>	You mean that if that were included in the source to a
>large program (ELM, for instance) you'd notice it was there
>before compiling it?  I doubt I would.

I wouldn't either, but to a great degree I'm depending on the collective
benefit of the net.  Were there a trapdoor buried in elm or some other
commonly used code from the net, there's a good chance that *somebody*
will notice it fast.  And woe to the person who got caught doing it!

Of course, this is another reason I'm more likely to blindly compile
stuff from comp.sources.{misc,unix} than alt.sources.



More information about the Alt.sources mailing list