I am posting this for people who don't understand the issues at stake:
The problem is that Trixbox developers have installed a script in your crontab to execute arbitrary command on your machine.
The script connects to their web site regularly and check if there are any commands to be executed on your machine, the output is encrypted and sent to trixbox. This is equivalent to a trojan horse program...
I wouldn't mind if they collected benign stats in a clearly defined manner. I DO MIND that they can execute any commands on my box... they don't even authenticate themselves...
The fact that kerryg doesn't understand this is aggravating!!! Kerry should buy some Schneier books and start reading.
I don't care about their intent... if they are compromised then anyone running trixbox will be affected.

Member Since:
2007-02-28