D&C GLug - Home Page

[ Date Index ] [ Thread Index ] [ <= Previous by date / thread ] [ Next by date / thread => ]

Re: [LUG] Linux Trojan Raises Malware Concerns - might be of interest

 

On Mon, 14 Jun 2010, Simon Waters wrote:

Now how do you compile the first C compiler... ;-)

You write it in Forth ;)

Aargh! The Horrors!

Oddly enough I've twice done stuff in Forth. Once was for fun though. The other was porting & modifying Suns OBP code to some custom Sparc hardware... I've almost recovered from that one...

All this proves is that reading the source code can't fix all the bugs
in your binaries, it doesn't stop it being a valid technique for
improving or checking code.

The problem with backdoors in source code is they can be awfully short
and hard to spot, although in the Linux "trojan" case it would be pretty
obvious to anyone who looked at a diff of the code.

And programs are too big these days too... I think it's unrealistic to actually inspect everything now - even though I compile a lot of stuff from scratch myself, I rarely delve into the code.

Gordon

--
The Mailing List for the Devon & Cornwall LUG
http://mailman.dclug.org.uk/listinfo/list
FAQ: http://www.dcglug.org.uk/linux_adm/list-faq.html