PDA

View Full Version : Attacks on Linux Package Managers?


tlu
July 16th, 2008, 10:00 AM
http://www.cs.arizona.edu/people/justin/packagemanagersecurity/attacks-on-package-managers.html

The recommendation to use only trustworthy official repositories is definitely correct. I don't know how other distros handle the mirror-server problem. But as far as Ubuntu is concerned, there are centralized security updates via security.ubuntu.com (and not via mirror servers). Thus, an attacker would have to perform a man-in-the-middle-attack between s.u.c. and my computer - very unlikely ;). For non-security updates the first sentence applies (i.e. to stick with the default servers or - if you're paranoid - with archive.ubuntu.com).

But again - other distros might be more affected. Any users of these distros who can deliver some insight?

lodore
July 16th, 2008, 05:28 PM
Hey Tomas, yesterday yast the package manager for opensuse told me there was a security issue with the package manager itself and then updated it along with various other updates.

Hermescomputers
July 18th, 2008, 11:59 AM
So far I can't see anything taking place in either of our Mandriva or Kubuntu boxes related to the package manager...

Hermescomputers
July 18th, 2008, 12:00 PM
sorry bout the double post... using XP Pro... since SP3, we get nothing but glitches across the board... I cant wait until I'm 100% linux on the entire infrastructure...

tlu
July 18th, 2008, 05:08 PM
{QUOTE-> I cant wait until I'm 100% linux on the entire infrastructure... <-QUOTE}

Yes,definitely a good choice.:thumb: