ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Security threats Toolkit

Intrusion detection team denies Trojan claim

Patrick Gray ZDNet Australia

Published: 22 Sep 2003 10:05 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

The author of Snort, an open-source Intrusion Detection System (IDS), Martin Roesch, has dismissed as untrue claims the software was 'trojaned' by attackers.

Roesch, who is also the chief technology officer of US-based IDS company Sourcefire, moved quickly to quell rumours in the security community that a hacking group had managed to insert back-door code into the Snort source-code repository.

"There is no back door in Snort nor has there ever been, everyone can relax," Roesch wrote in a posting to the full disclosure security mailing list.

Attackers had breached one of Roesch's systems, he admits, but that was a low-security shell server -- used by members of the Snort team and their associates to access services such as IRC without exposing their own machines to risk -- located in his basement, 37km away from the Snort code repository.

"If you're wondering 'how do you know the code isn't backdoored?', since we know that that server is an 'at risk' server, we're not in the habit of checking code into [the Snort code repository] from there. If that's not good enough for you, Snort has been through three code audits since March -- one Sourcefire internal, two third-party external -- and there are most definitively no back doors in the code, nor were there any," Roesch added.

Trojans have been found in several open-source projects over the last year, including those found in Sendmail and OpenSSH. Malicious code was also found in the libpcap and tcpdump libraries -- software which is required by the Snort IDS to operate.

Australian security consultant Daniel Lewkovitz says that the mere fact that a rumour like this could turn out to be true, even though it looks unlikely in this case, means the issue at least warrants discussion. "A lot of threats haven't changed that much, but what has changed is normal people's awareness and attitudes to it. I think anything that makes people more aware of relevant issues and relevant threats a good thing," he told ZDNet Australia. 

There's nothing necessarily wrong with listening to a rumour so you can check it out for yourself, Lewkovitz says, as long as the source of the rumour is at least somewhat credible. "If there was a threat I'd want to know about it," he said. "If it came from a reliable source I'd be much more likely to give it credence than the paranoid rants of tin-foil-hat-wearing conspiracy theorists."

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Dell

Did you find this article useful?
89 out of 141 people found this useful


Company/Topic Alerts

Create a new alert from the list below:







Related Jobs

Control Officer

Control Officer IT Services Bradford, West Yorkshire For every IT system or service thats in place at Morrisons, our ability to maintain controlled ...

Housing Development Officer North West 6 Months Contract

My client is a social housing provider in the north looking for a Housing Development Officer. The Housing Development Officer will be able to ...

Senior QA (Quality Assurance) Officer, Biopharm Company, Staffs

Senior QA (Quality Assurance) Officer, Biopharmaceutical Company, Staffordshire/Oxfordshire Senior QA (Quality Assurance) Officer: My client is a ...

Featured Talkback

What was achieved there is recognised to be of fundamental importance to both winning the war (Churchill visited to say 'thank you' to them) and the development of the computer. Maybe Bill Gates doesn't want to support this museum because it underlines where electronic computing started i.e. here, not the U.S.

By: 1000103773

Read full story:
Bletchley Park faces bleak future

Sentry Posts Blog

Mobile Security Expert: Your Camera Ph...

Mobile Security Expert: Your Camera Phone Got Hacked Author: Eric Everson, Founder MyMobiSafe.com Have you ever heard someone say “I’d like to be a fly on the wall in that room.”?... More

Post a comment

Skype - The Roach Motel

Here is an interesting article from The National Business Review, pointing out once again that you can never delete a Skype account. Never. Period. This is something I am familiar... More

Post a comment

The vPhone: Why Visa Should Go Mobile

The vPhone: Why Visa Should Go Mobile Author: Eric Everson, Founder MyMobiSafe.com With all of the success of Apple’s iPhone, there is a growing case to support a company like Visa... More

Post a comment