TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

Backdoor in vsftpd download

44 点作者 mrud将近 14 年前

4 条评论

nodata将近 14 年前
"Signatures aside, I also took the liberty of moving most of the vsftpd site and latest download to a hosting provider I have more faith in:"<p>Would be interesting to see <i>how</i> the site was compromised.<p>This is interesting for two reasons:<p>i) I thought he owned the place he hosted<p>ii) This won't help if he had a weak password
rlpb将近 14 年前
Verifying the signature wouldn't have been that helpful. A different attacker might generate a similar key with the same name and sign the archive with that. How many of you check signature fingerprints (and how?) or have a chain of trust that leads to the maintainer?
评论 #2726327 未加载
maurycy将近 14 年前
A pun I cannot resist: the backdoor is in the FTP protocol itself, which is, no matter how secure the deamon serving it is, completely insecure.
评论 #2725769 未加载
评论 #2725755 未加载
trezor将近 14 年前
Boohoo. FTP is by design an insecure and overly complex protocol, and any firewall-admins nightmare to handle.<p>Anyone using FTP in this time and age should be prepared for pain. That the pain is now related to a bug in a software-implementation instead of a bug in the base protocol-design doesn't really shift the pain that much. It's FTP and FTP is pain. You do get what you asked for.<p>If you want security and something simple to administer, just go for SSH and SCP. Granted, it wont allow anonymous downloads, but if that's all you need, why not just go with HTTP in the first place?