home *** CD-ROM | disk | FTP | other *** search
- Newsgroups: comp.security.misc
- Path: sparky!uunet!think.com!cass.ma02.bull.com!estrella
- From: estrella@cass.ma02.bull.com (Gustavo Estrella)
- Subject: Re: early Trojan Horse
- Message-ID: <1992Nov20.192026.20242@cass.ma02.bull.com>
- Organization: Bull World Wide Information Systems Inc.
- References: <1992Nov18.202710.9652@mcs.kent.edu> <956@dsbc.icl.co.uk> <1992Nov19.194057.19996@exlog.com>
- Date: Fri, 20 Nov 1992 19:20:26 GMT
- Lines: 33
-
- In article <1992Nov19.194057.19996@exlog.com> mcdowell@exlog.com (Steve McDowell) writes:
- >
- >In message <956@dsbc.icl.co.uk> kev@dsbc.icl.co.uk (Kevin Walsh) writes:
- >>In article <1992Nov18.202710.9652@mcs.kent.edu> keithf@Nimitz.mcs.kent.edu (Keith Fuller) writes:
- >>
- >>> I heard that early UNIX systems came with a Trojan Horse.
- >>> As I remember, the C compiler would compile one of the utilities
- >>> in a way that would give a knowledgable person entry into any UNIX
- >>> system.
- >>
- >> As I remember it, cc used to recognize a peice of code as being
- >> from the login program. When you compiled login, the resulting
- >> executable would have a back door login in it.
- >
- >Well, I don't know if that was ever implemented and I'd be very surprised if it
- >ever made it out of the lab if it was.
- >
- >This means of attack was discussed by Dennis Ritchie in an early papaer (mid-70's)
- >on UNIX security as an option that's available to would-be-crackers with source code.
- >If I remember correctly, the paper was distributed with the Version 7 manual set.
-
- I remember reading somewhere aboit this. As I recall it, in addition to the
- cc program looking for the login code it would also look for a recompilation
- of the cc program itself. This way, as people would become suspisious and
- recompile the compiler with clean source, it would include the code to
- look for the login code.
-
- I though that the code spread outside of the Bell Labs.
-
- --------------------------------------------------------------------------
- Gus Estrella - Groupe Bull Worldwide Information Systems
- --------------------------------------------------------------------------
-
-