Forum     

Go Back   Digit Technology Discussion Forum > News > Technology News
Register FAQ Calendar Mark Forums Read

Technology News News from the world of technology that our members stumble across. NOTE: Sources to be mentioned at the beginning of each post.


Reply
 
LinkBack Thread Tools Display Modes
Old 12-09-2011, 10:54 AM   #1 (permalink)
Section Moderator
 
gopi_vbboy's Avatar
 
Join Date: Mar 2007
Location: Hyderabad
Posts: 1,187
Default Linux.com and The Linux Foundation taken offline following security breach


Quote:
Rootkit not detected for 17 days

By Dan Goodin in San Francisco • Get more from this author

Posted in Enterprise Security, 31st August 2011 22:35 GMT

Updated Multiple servers used to maintain and distribute the Linux operating system were infected with malware that gained root access, modified system software, and logged passwords and transactions of the people who used them, the official Linux Kernel Organization has confirmed.

The infection occurred no later than August 12 and wasn't detected for another 17 days, according to an email John "'Warthog9" Hawley, the chief administrator of kernel.org, sent to developers on Monday. It said a trojan was found on the personal machine of kernel developer H Peter Anvin and later on the kernel.org servers known as Hera and Odin1. A secure shell client used to remotely access servers was modified, and passwords and user interactions were logged during the compromise.

“Intruders gained root access on the server Hera,” kernel.org maintainers wrote in a statement posted to the site's homepage shortly after Hawley's email was leaked. “We believe they may have gained this access via a compromised user credential; how they managed to exploit that to root access is currently unknown and is being investigated.”

The maintainers said they believed the repositories used to store Linux source code were unaffected by the breach, although they said they were in the process of verifying its security. They went on to say the potential damage that can be done by rooting kernel.org is less than typical software repositories because of safeguards built in to the system.

“For each of the nearly 40,000 files in the Linux kernel, a cryptographically secure SHA-1 hash is calculated to uniquely define the exact contents of that file,” the statement explained. “Once it is published, it is not possible to change the old versions without it being noticed.”

Each hash is stored on thousands of different systems all over the world, making it easy for users to check the validity of Linux files before running them on their machines.

Linux kernel maintainers didn't respond to an email seeking comment for this story, but two security researchers who were briefed on the breach said the infected systems were hit by a self-injecting rootkit known as Phalanx, variant of which has attacked sensitive Linux systems before.

“It's sort of surprising,” said Jon Oberheide, one of the Linux security researchers briefed on the breach. “If this was a very sophisticated attack, it's very unlikely that the attackers would use an off-the-shelf rootkit like Phalanx. Normally if you were to target a high-value target you would potentially use something that's more more tailored to your specific target, something that's not going to be flagged or potentially detected.”

Fellow security researcher Dan Rosenberg said he was also briefed that the attackers used Phalanx to compromise the kernel.org machines. Both Rosenberg and Oberheide confirmed that Hawley's email was sent to Linux kernel developers. It was also signed using Hawley's private encryption key.

The first indication of a compromise came shortly after an error message related to Xnest was displayed on a machine that didn't have the X Window application installed. Linux maintainers are advising developers to carefully investigate any systems that don't have the the program installed and display the /dev/mem message anyway.

Been down this road before
It's not the first breach to hit a venerable organization that distributes open-source software that thousands of sensitive organizations rely on to remain secure. In December, GNU Savannah, the main source-code repository for the Free Software Foundation, was taken down following a hack that compromised passwords. Admins at the time couldn't rule out the possibility the attackers gained root access

And in April 2010, the Apache Software Foundation, which maintains the world's most widely used webserver, suffered a direct targeted attack that captured he passwords of anyone who used the website's bug-tracking service over a three-day span. It was the second major compromise of Apache.org in eight months.

Kernel.org members have taken the infected servers offline and are in the process of completely reinstalling the operating system on each machine in the organization. They are also working with all 448 users of kernel.org to change their authentication credentials, including SSH keys. They have also notified authorities in the US and Europe to assist in the ongoing probe of the breach.

“The Linux community and kernel.org take the security of the kernel.org domain extremely seriously, and are pursuing all avenues to investigate this attack and prevent future ones,” Wednesday's statement said. ®


Kernel.org Linux repository rooted in hack attack • The Register
gopi_vbboy is offline   Reply With Quote
Advertisements. Register and be a member of the community to get rid of them.
Advertisement

Old 12-09-2011, 11:14 AM   #2 (permalink)
BMG ftw!!
 
d6bmg's Avatar
 
Join Date: Aug 2011
Location: Kolkata
Posts: 3,840
Default Re: Linux.com and The Linux Foundation taken offline following security breach

Well, I knew this as I've already got a warning mail from them regarding the same for being an active user/member there but never thought of publishing the news as it is not too serious to be concerned about.
d6bmg is online now   Reply With Quote
Old 12-09-2011, 11:37 AM   #3 (permalink)
Section Moderator
 
gopi_vbboy's Avatar
 
Join Date: Mar 2007
Location: Hyderabad
Posts: 1,187
Default Re: Linux.com and The Linux Foundation taken offline following security breach

if kernel.org is comprosmised....how can we trust the distro kernels...
gopi_vbboy is offline   Reply With Quote
Old 12-09-2011, 11:45 AM   #4 (permalink)
In The Zone
 
socrates's Avatar
 
Join Date: Mar 2007
Location: Mumbai
Posts: 387
Default Re: Linux.com and The Linux Foundation taken offline following security breach

Quote:
Originally Posted by gopi_vbboy View Post
if kernel.org is comprosmised....how can we trust the distro kernels...
So true! I was about to post this. Real sad
__________________
be what you are
and say what you feel
bcoz those who mind, don't matter
and those who matter, don't mind !!
socrates is offline   Reply With Quote
Old 12-09-2011, 11:54 AM   #5 (permalink)
the m0nk who sold his PC!
 
MatchBoxx's Avatar
 
Join Date: Apr 2011
Location: Kolkata...the ultimate city!
Posts: 516
Default Re: Linux.com and The Linux Foundation taken offline following security breach

^^follow their advice. That's all we can do :/
__________________
Intel i5-2400 || ASUS P8H77-M || G.Skill RipjawsX 8GB (4GBx2) || MSI HD6850 Cyclone PE || Corsair GS600 || Cooler Master Elite 431(Side Panel) || Dell ST2220L || Edifier C2 || APC 1.1 kVA || Seagate GoFlex 1TB

(WBUT semester routine announced. I'm OFF for the time being.)
MatchBoxx is online now   Reply With Quote
Old 12-09-2011, 03:14 PM   #6 (permalink)
God of Mistakes...
 
Garbage's Avatar
 
Join Date: Dec 2005
Location: Pune, Maharashtra
Posts: 1,923
Default Re: Linux.com and The Linux Foundation taken offline following security breach

Quote:
Originally Posted by gopi_vbboy View Post
if kernel.org is comprosmised....how can we trust the distro kernels...
You don't need to worry, because Linux kernel source code is NOT hosted on kernel.org
__________________
Registered Linux User #468778
----------------------------------
http://twitter.com/_Garbage_
Garbage is offline   Reply With Quote
Old 12-09-2011, 10:31 PM   #7 (permalink)
BMG ftw!!
 
d6bmg's Avatar
 
Join Date: Aug 2011
Location: Kolkata
Posts: 3,840
Default Re: Linux.com and The Linux Foundation taken offline following security breach

Quote:
Originally Posted by gopi_vbboy View Post
if kernel.org is comprosmised....how can we trust the distro kernels...
That's totally different. You should not worry about that.
d6bmg is online now   Reply With Quote
Reply

Bookmarks

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


 
Latest Threads
- by Who
- by Tech&ME
- by icebags
- by Tenida
- by clmlbx

Advertisement




All times are GMT +5.5. The time now is 08:27 PM.


Powered by vBulletin® Version 3.8.7
Copyright ©2000 - 2012, vBulletin Solutions, Inc.

Search Engine Optimization by vBSEO 3.3.2