Hacked or not appendice

Alex Povolotsky tarkhil at webmail.sub.ru
Sat Jun 12 13:46:34 GMT 2004


On Sat, 12 Jun 2004 13:03:07 +0000
Thordur Ivar <thib at mi.is> wrote:

TI> I have on a CD a number of binarys ( sources actually ) ( e.g. ls,
TI> find, grep, awk, sed, locate e.t.c. ) and when I belive that a
TI> machine has been cracked I remove the network cable from that
TI> machine and mount the cdrom build the sources and start looking. If
TI> I need something in that process I put it on my USB memstick from a
TI> 'trusted machine' and move it by hand over. 

When I was unable to do the same thing, I've recompiled md5 tool from freshly fetched sources and used it to test utilities. I don't beleive in attacker catching thr build process transparently...

-- 
Alex.


More information about the freebsd-security mailing list