[MPlayer-dev-eng] autosh*t @ freshmeat

Petr Tomasek tomasek at etf.cuni.cz
Sun Jun 22 11:37:57 CEST 2003


> (BTW, have you ever stopped to think how many trojans might be hiding
> in various packages' autoconf-generated configure scripts, since no
> one ever actually reads the output? Imagine if the developer in charge
> of releases got rooted and some trojan code was installed in their
> system-wide ac m4 macros... Natually a handwritten configure script
> does not have this problem since every change is visible as it's
> committed to CVS.)

If you compromise the compiler, you even don't need Makefile to
promote the trojan ;-)


--
Petr Tomasek, http://www.etf.cuni.cz/~tomasek/




More information about the MPlayer-dev-eng mailing list