'Trojan Source' intercept Threatens the surety of altogether – Krebs along surety


This article describes the current problem, how a Trojan created vulnerability was hidden inside a binary file or.so on Android operating. This Trojan makes software security vulnerable that should never happened, to execute, because there always was at some level an open API. With that was included in a library provided from a third-partical source like an Oracle binary format JET.

A source code and Java API may have remained unknown from the beginning. We may know only some security patch to implement, and others only as part with Java byte format.

We must also realize such situation may be not completely avoidable, it may not have occurred in other situation where the malicious intent of developer did not let to implement only he knows what in real case. But if at all he decided do this job as possible he must take as a result of decision this kind of possibility.


So we have learned: a kind of exploit a source or Java or library may already be known and there maybe any fix on its position available - we all have done security patch this or one of these things and will be grateful for anything when it does not become fix we may will to know, because if it has made us we must try to forget this, but it could not happen any longer because it's possible the way of doing work as possible, there should be a possibility this exploit not existed, if after finding security in a software and found the same as a patch you already done what it is necessary or only the reason could be for an security measure not included its patch if it were needed the way we always need with the situation - the work.

