[Snort-users] libcap,libnet

Matt Kettler mkettler at ...4108...
Fri Dec 27 09:00:02 EST 2002

The direct source at tcpdump.org, and most mirrors, should be LONG since 
clean of this. The trojan incident was in mid November.

If you have doubts, this article has the md5sums of both the trojaned, and 
untrojaned tarballs:


With trojan:
MD5 Sum 73ba7af963aff7c9e23fa1308a793dca  libpcap-0.7.1.tar.gz

Without trojan:
MD5 Sum 0597c23e3496a5c108097b2a0f1bd0c7  libpcap-0.7.1.tar.gz

You can also grep the ./configure script for "mars.raketti.net" which is 
the site the trojan downloads some extra code from.

At 02:50 PM 12/27/2002 +0300, Denis A. Kirin wrote:
>Hi All.
>Where can I get Libcap and Libnet packages... without trojan?
>Thanks in advance,
>This sf.net email is sponsored by:ThinkGeek
>Welcome to geek heaven.
>Snort-users mailing list
>Snort-users at lists.sourceforge.net
>Go to this URL to change user options or unsubscribe:
>Snort-users list archive:

More information about the Snort-users mailing list