[39775] in bugtraq
Re: Installation of software, and security. . .
daemon@ATHENA.MIT.EDU (joop gerritse)
Wed Jul 20 22:53:12 2005
From: joop gerritse <jjge@xs4all.nl>
To: bugtraq@securityfocus.com
Date: Tue, 19 Jul 2005 07:17:33 +0200
In-Reply-To: <42DAB70A.6010207@web.de>
MIME-Version: 1.0
Content-Type: text/plain;
charset="utf-8"
Content-Disposition: inline
Message-Id: <200507190717.33600.jjge@xs4all.nl>
Content-Transfer-Encoding: 8bit
On Sunday 17 July 2005 21:52, Klaus Schwenk wrote:
> I had some similar thoughts on that topic recently and do agree with you
> that the current habit of installation handling has several problems.
>
> First of all (at least on MS-based OS's) it's pretty hard to tell what
> exactly is done by the installer. Even harmless software does not always
> keep a log of its actions nor is it observed by some system service. As
Occasionally, I have been using INCTRL5 to check at least the most obvuious
items for change before and after installation.
--
Joop Gerritse
Mühlenstraße 11
D-47546 Kalkar-Wissel
Germany
+49 2824 971487
http://www.jjge.nl