Skip site navigation (1)Skip section navigation (2)
Date:      Sun, 28 Jan 2007 14:13:51 -0600
From:      Paul Schmehl <pauls@utdallas.edu>
To:        Pekka Riikonen <priikone@iki.fi>
Cc:        "Freebsd Ports: Archivers" <ports@freebsd.org>, security@silcnet.org, aquatique-ports@rambler.ru
Subject:   Re: Problem with devel/silc-toolkit
Message-ID:  <103D5836493CBF0EACA17AE1@paul-schmehls-powerbook59.local>
In-Reply-To: <Pine.NEB.4.64.0701280942560.23771@otaku.Xtrmntr.org>
References:  <3B27E5D772A78D81D72D9420@paul-schmehls-powerbook59.local> <20070128014441.GA76439@atarininja.org> <D2F9DABD9A545B74551F4D18@paul-schmehls-powerbook59.local> <20070128024514.GA79142@atarininja.org> <2A54A37FBF8B6E7EE4DEAA5F@paul-schmehls-powerbook59.local> <20070128033157.GB79646@atarininja.org> <A2FDF255F8D7771162FF6E97@paul-schmehls-powerbook59.local> <Pine.NEB.4.64.0701280942560.23771@otaku.Xtrmntr.org>

next in thread | previous in thread | raw e-mail | index | archive | help
--==========CD3AFD0E86C586C0B559==========
Content-Type: text/plain; charset=us-ascii; format=flowed
Content-Transfer-Encoding: quoted-printable
Content-Disposition: inline

--On January 28, 2007 9:55:42 AM +0100 Pekka Riikonen <priikone@iki.fi>=20
wrote:
> :
> Thanks for letting us know about these issues, but we have not updated
> the  files at silcnet.org since they were put up there.  They were last
> modified Dec 19 2005.   I suspect you had some local problem or download
> problem or some mirror was corrupted.  I also verified the files this
> morning and the md5sums are as follows:
>
Well now you have me even more concerned.  I downloaded the file directly=20
from silcnet.org using both the port and ftp, and I also downloaded the=20
file on my Mac here at home using ftp to pull the file both from the http=20
and the ftp download sites.  In all four cases, the md5sum and the sha256=20
sum did not match the file that was downloaded.  Furthermore, the size of=20
the file was a meg less than it was supposed to be.

Then, while I was downloading copies from some of the mirrors to check=20
them, the file from silcnet.org suddenly matched the md5sum and the size=20
of the legitimate file.  While it's entirely possible that *both* my=20
FreeBSD box *and* my Mac were somehow screwed up, it's hard to believe=20
that *multiple* downloads on both boxes would arrive at the same results=20
and then suddenly they would change, yet nothing changed at the=20
distribution site.  It's certainly odd enough to warrant a thorough=20
investigation, I would think.

There was obviously a problem somewhere, but I'm not convinced it was on=20
both of my boxes and nowhere else.

Paul Schmehl (pauls@utdallas.edu)
Senior Information Security Analyst
The University of Texas at Dallas
http://www.utdallas.edu/ir/security/

--==========CD3AFD0E86C586C0B559==========--




Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?103D5836493CBF0EACA17AE1>