Subject: CGAL users discussion list
List archive
- From: maurice oustache <>
- To:
- Subject: [cgal-discuss] GhostNet
- Date: Wed, 1 Apr 2009 09:02:44 +0200
- Domainkey-signature: a=rsa-sha1; c=nofws; d=gmail.com; s=gamma; h=mime-version:date:message-id:subject:from:to:content-type; b=MyQTK2J9iZkrtrM4RI3vfhvjUNaedOT8pxgrX0hVNl4AEEc/YPc5UvPQwBOZE70cTR LMyYzs80xPVm5l/wHJVdE6Bp7gOSPlVx5oYoA1FTZKOn8EaN5qvo63+iQGguyzJS1VNF OxwPT/RC0pUK6nOlanZ+tceCPmWuWSChU9ank=
Dear CGAL users,
it seems that the GhostNet spying operation, http://en.wikipedia.org/wiki/Ghostnet ,
discovered by the Munk Center for International Studies at the University of Toronto,
mainly infiltrated machines through the trojan horses of Open Source Software
projects.
Our organization (DST) downloaded and analyzed several software packages,
where French research labs like INRIA are implied, and we discovered that
among several other projects the CGAL project was chosen as a vector of infection,
probably due to its worldwide users.
The file CGAL/basic.h contains some "invisible" code, which, when compiled, every
time an application that includes the header file is executed, sends sensible
information about the environment of the running application via UDP broadcasts
(in order not to reveal a fixed destination IP address).
Malgre the source code distribution, not even the developers were aware of it
(Last night we interrogated several developers at Inria and GeometryFactory). The
reason is simple: CGAL/basic.h is not just plain ascii but encoded in UTF-EBDIC,
which makes that the subtext is not displayed in development environnements
like emacs, vim, DeveloperStudio ou Eclipse. In fact, we discovered it when
we loaded the header file in the text editor of DerriereLaLune, the French fork
of Eclipse.
We *urge* you to replace CGAL-3.4/include/CGAL/basic.h with the attached clean
version in order to avoid further problems with GhostNet.
Cordialement,
Maurice Oustache
http://www.linkedin.com/in/mauriceoustache
Attachment:
basic.h
Description: Binary data
- [cgal-discuss] GhostNet, maurice oustache, 04/01/2009
- Re: [cgal-discuss] GhostNet, naresh, 04/01/2009
- Re: [cgal-discuss] GhostNet, Ruud op den Kelder, 04/01/2009
- Re: [cgal-discuss] GhostNet, Sean McDuffee, 04/01/2009
Archive powered by MHonArc 2.6.16.