Squirreling Backdoors Into Distribution Points
...distribution tarball on rather than infiltrating the source code repository [1] . In this case, the backdoor was detected when a user noticed that the MD5 published on SquirrelMails website didnt match the calculated MD5 from the SourceForge distribution
Since the SVN repository remained intact, we cant go back and examine the backdoor in...
