On Sat, Oct 29, 2005 at 08:13:43PM +0300 or thereabouts, Stefan Tanurkov wrote:
 
> > so when you download something, that says some normal program, you don't
> > know what you have installed, even though it shows familiar .exe programs.
 
> Well, it's not true for signed code (which is contained in .MSI files),

good point. 

> but I agree that unsigned executables cannot be trusted before we have
> verified all of them.
 
even each HTML page that lists any directs for any downloads for all RT
products should be checked (HTML coding), so that when it says e.g.
tbbeta3.x.x.exe, or Batpost.exe, that it will not be redirected to another
site for downloading which would contain a malicious exe. Any hack is a
pain in the butt :) I'm sure you have a handle on it, and who did it from
the logs. Here, IIRC, if it causes over $5000 in lost revenue, you can get
the FBI involved as an active case.. Hopefully, you have something similar
there. 

-- 
Gary


________________________________________________________
 Current beta is 3.62.05 | 'Using TBBETA' information:
http://www.silverstones.com/thebat/TBUDLInfo.html
IMPORTANT: To register as a Beta tester, use this link first -
http://www.ritlabs.com/en/partners/testers/

Reply via email to