28 December 2010


This writeup does little more than convince readers that because the tarballs' checksums were not changed recently, then it must go to follow by implication that there is no backdoor in the ettercap project.

In fact, this is quite contrary to the situation at hand -- If the source of ettercap in earlier revisions (say, 5+ years ago as the zine claims) contained a backdoor or vulnerability which was never discovered nor disclosed, it is likely to still reside within the project. Further, checking to ensure that the SHA1 sums of these tarballs are the same now as they were then (when??) only proves that the contents of said tarballs has not changed since ALoR's last pull from the project's repository.

It seems that this article is very misleading and in this industry, a false sense of security is much worse than FUD.

