Linked by Ben Mazer on Wed 15th Oct 2003 20:58 UTC
Linux A few months ago I was a Slackware Junkie. I loved it, and laughed at those who used 'more automatic' distributions (ok, I didn't actually laugh). Then Arch Linux 0.5 came out and I was very intrigued by it. I was getting tired of having to compile updated packages myself.
Permalink for comment
To read all comments associated with this story, please click here.
PKGBUILD security
by terrapin on Fri 17th Oct 2003 15:00 UTC

"Just change the source url to get the 'pristine' sources to an alternate url which gets tainted sources."

Yes that true. But that would only occur if you don't take the time to read the PKGBUILD file. As stated before it's very easy to read. It will be very obivous to anyone who reads the PKGBUILD file that ftp:\ftp.someprogram.comprogram.exe is replaced with http:\hacker.malware.comtrojan.exe.