Hi everybody,
I just checked it double: YES the openssh-3.4p1.tar.gz on ftp.openbsd.org is TROJANED!!! I downloaded our versions here just after there
were released from the OpenSSH team, these ones seem to be clean. BUT: The version which is actually available on ftp.openbsd.org is
NOT clean! Or did I make a mistake in my analysis?!?
So is this the time to say good bye to OpenSSH?!? ;))
Christoph
1.8.2002 10:21:21, Len Rose
Not implying that SuSE has this problem (it doesn't) but you may wish to read this:
http://lists.netsys.com/pipermail/full-disclosure/2002-August/000734.html
-- .-. Ruhr-Universitaet Bochum /v\ L I N U X Lehrstuhl fuer Biophysik // \\ >Penguin Computing< c/o Christoph Wegener /( )\ Gebaeude ND 04/Nord ^^-^^ D-44780 Bochum, GERMANY Tel: +49 (234) 32-25754 Fax: +49 (234) 32-14626 mailto:cwe@bph.ruhr-uni-bochum.de http://www.bph.ruhr-uni-bochum.de