If you download files with a .bz2 extension with Microsoft IE for some [EMAIL 
PROTECTED] reason it renames the extension to .tar. Just rename the file after you 
download it from filename.tar.tar to filename.tar.bz2.

Hope this helps.

Russell Premont

-----Original Message-----
From: [EMAIL PROTECTED]
[mailto:[EMAIL PROTECTED] Behalf Of Sam
Varshavchik
Sent: Monday, March 24, 2003 8:22 PM
To: Peter Diffey
Cc: [EMAIL PROTECTED]
Subject: [maildropl] Re: authlib bug - POSSIBLE TROJAN


Peter Diffey writes:

> 
> It seems that there is a serious bug in the courier-imap authdaemon - at 
> least that seems to my first impression.
> 
> 
> 
> I did a standard configure/make/install of courier-imap-1.7.1.20030319.tar.tar
> 
> My system is MDK 8.2
> 
> thereafter I found that my system security was wide open, and no passwords 
> are required for telnet, rsh or anything else.
> 
> I noticed that the /usr/lib/authlib/auth* executables have been replaced, 
> this  seems to have been done by authlib/Makefile.am
> 
> I believe that the authdaemon may have been hacked
> 
> It could of course be some sort of installation failure, however this in 
> itself is dangerous, and is potentially as damaging as a trojan.
> 
> Please investigate

A couple of things:

A) This is the maildrop list, not the Courier-IMAP list

B) There is nothing called "courier-imap-1.7.1.20030319.tar.tar" that's 
available for download.  For quite some time, only bzip2-compressed tarballs 
were distributed.

C) Nothing ever gets installed in '/usr/lib/authlib', after a "a standard 
configure/make/install".

D) A checksum of courier-imap-1.7.1.20030319.tar.bz2 currently available for 
download matches my own checksum.

Conclusion: please make some effort to obtain some facts by YOURSELF, before 
going off, like that.



-------------------------------------------------------
This SF.net email is sponsored by:
The Definitive IT and Networking Event. Be There!
NetWorld+Interop Las Vegas 2003 -- Register today!
http://ads.sourceforge.net/cgi-bin/redirect.pl?keyn0001en
_______________________________________________
Courier-maildrop mailing list
[EMAIL PROTECTED]
https://lists.sourceforge.net/lists/listinfo/courier-maildrop



-------------------------------------------------------
This SF.net email is sponsored by:
The Definitive IT and Networking Event. Be There!
NetWorld+Interop Las Vegas 2003 -- Register today!
http://ads.sourceforge.net/cgi-bin/redirect.pl?keyn0001en
_______________________________________________
courier-users mailing list
[EMAIL PROTECTED]
Unsubscribe: https://lists.sourceforge.net/lists/listinfo/courier-users

Reply via email to