Re: Downloading files



chuckcar <chuck@xxxxxxx> wrote:

Retaining little worries about a piece of untrustworthy software
you've fetched from somewhere, for no better reason than having its
source code, is a truly _excellent_ way to fool yourself and shoot
yourself in the foot. The reasons should be obvious. If not, go and
security-audit the source code of the next five desktop applications
you use. (For extra fun, make sure they have to parse data from
public networks, and go over those input-validation routines
carefully!)

Tell you what, you find *one* named piece of software fitting this
character on sourceforge.net, freshmeat.net or gnu.org and I'll
willingly admit I was misinformed on the matter, but until you do, you
might as well be talking about some code somebody dreged out of a
newsgroup that only posts code for lovers of viri.

o mpg123 pre0.59s beta was vulnerable to buffer overflow induced by
trojaned (specially malformed) MP3 files played using it, having
binary code in the MP3 frame header that invokes a shell and recursively
deletes the user's home directory. Some showoff who noticed this
bug actually coded a piece of exploit code against it called
JBells (aka Jbellz), that you'll find in some of the more
comprehensive lists of Linux malware. Such as *ahem* mine.

OK, what did I win, Chuck? ;->

.



Relevant Pages

  • Re: Downloading files
    ... for no better reason than having its ... source code, is a truly _excellent_ way to fool yourself and shoot ... newsgroup that only posts code for lovers of viri. ... (setq (chuck nil) ...
    (comp.os.linux.setup)
  • Re: packagemaker script assistance needed.
    ... Santa Claus wrote: ... Is there a reason you're conditionalizing the whole block instead of one ... the reason my program source code is so long. ...
    (comp.sys.mac.programmer.help)
  • Re: ASCII schematics from LTSpice
    ... >Is there any reason it shouldn't compile under linux? ... be will depend a lot on how closely aligned the schematic semantic designs are. ... If you do take a whack at this, I'd appreciate any feedback on the source code ... Jon ...
    (sci.electronics.basics)
  • Re: Message unknown: "Warning: initial dialog data is out of range."
    ... the search for the reason of the warning is ... I always just search the source code. ... >context than the generic message string, which might be "Resource was not ... MVP Tips: http://www.flounder.com/mvp_tips.htm ...
    (microsoft.public.vc.mfc)
  • Re: Torture - A lawful good act?
    ... son did not shoot. ...  He was shot to death with five different rifles. ... a CCL is because you want to protect your life, your family, your ... The reason to have it is to defend ...
    (rec.games.frp.dnd)