[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: AW: [cobalt-security] Unofficial PHP 4.1.2 PKG available



My 2 cents worth...

Michael may have been the first one to report the spyware on the newsgroup, but the developer Andres was already confronted about it after we installed the pkg on Sunday New Zealand time.

The way we found out about it was by simply checking our logs after it was installed, we noticed in the mail logs that an email went out to Andres and Cobaltnet via root.
Andres was immediately contacted by us and asked to explain his actions...

So how many people have been checking their logs regularly then? Speak about security :)

Andres explination was as you see here - he was following the guide lines laid down for creating pkg's.

I thanked Andres for explaining this and have also requested that I see a copy of the email that was automatically sent out.

Now before I even had time to get on to the newsgroup the "witch hunt" had started.

I think everyone should lay off the man, he's provided a package that was non-exsistant for us RaQ3 users, he's explained his actions and has since removed the "required" registration email routine.


Regards

Chae