openssl shared libs

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



Just one opinion:  If your attacker can replace the libraries, they have 
root access.  They can hook into the keyboard, replace your application, 
etc.  If they have root access, you've already lost.

OTOH, static link means that your application won't automatically get 
security updates.

On 6/20/2016 11:05 AM, Mirko Fit wrote:
>
> I've got some questions on the shared build of openssl.
> Is it safe to use the shared libraries libssl.so and libcrypto.so?
> Couldn't the shared libs be replaced by manipulated ones that intercept
> my calls and steal the passwords?
> I was wondering why every linux distrubutions comes with these shared
> libs if the scenario I described was possible.
>
> Thanks,
> Mirko
>




[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

[Index of Archives]     [Linux ARM Kernel]     [Linux ARM]     [Linux Omap]     [Fedora ARM]     [IETF Annouce]     [Security]     [Bugtraq]     [Linux]     [Linux OMAP]     [Linux MIPS]     [ECOS]     [Asterisk Internet PBX]     [Linux API]

  Powered by Linux