ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Desktop platforms Toolkit in association with http://ad.doubleclick.net/clk;205413468;14699245;m?http://adfarm.mediaplex.com/ad/ck/2397-58840-22058-14

Debian team confirm Linux flaw allowed attack

Published: 02 Dec 2003 11:15 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

The Debian Project warned on Monday that a flaw in the Linux kernel helped attackers compromise four of the open-source software project's development servers.

During several intrusions on 19 November, the flaw enabled an attacker who already had access to a server to remove the limitations that protected the system from everyday users. The technique is known as a privilege escalation.

Members of the development team found the flaw in September and fixed the latest version of the core Linux software, or kernel. The fix came a bit late, however. The latest version of the kernel, 2.4.23, was released Friday, eight days after the Debian breach.

The Debian Project, which uses only truly open-source software in its make-up, stressed that the breaches hadn't affected the project's code base.

"Fortunately, we require developers to sign the upload [software] digitally," said Martin Schulze, a developer and member of the project. "These files are stored off-site as well, which were used as a basis for a recheck."

The development team promised to lock all developer accounts until the flaw had been found and fixed. The team published patches for the flaw on Monday as well but didn't specify when the accounts would be unlocked.

The unknown attacker compromised at least four servers. The systems -- known as Master, Murphy, Gluck and Klecker -- had maintained the open-source project's bug tracking system, source code database, mailing lists, Web site and security patches.

The attacker gained access to one of the systems by compromising a developer's computer and installing a program to sniff out the characters typed on the developer's keyboard, according to a postmortem analysis the team published on Friday. When the programmer logged into the klecker system, the attacker recorded his password.

Using the September flaw, the attacker gained owner privileges on Klecker. This is frequently referred to as "owning" the system. The flaw -- in a part of the kernel that manages memory -- allows only users that already have access to the system to raise their privileges. Such flaws are less critical than vulnerabilities that give an outside attacker access to a server and so are fixed less quickly.

The attacks have been the latest levelled at open-source software. In early November, an attacker attempted to corrupt the Linux kernel with a coding error that would have created a flaw similar to the one that affected the Debian Project. A year ago, malicious attackers placed spyware into a popular open-source tool, Tcpdump. Several other known attacks have also been executed against other open-source projects.

The latest bug has been fixed in the most recent version of the Linux kernel, 2.4.23, and has also been patched in the next generation of Linux since 2.6.0-test6, which was released in late September.

Despite a two-month delay in releasing a patch, Ian Murdock, the founder of Debian and the chairman of Linux distribution maintenance provider Progeny, praised the project team.

"All in all, the way the Debian guys handled the situation has been admirable: They have been open with what they found out, and the speed at which they have found things out has been quite quick," he said. Murdock is a developer on the team but no longer has day-to-day administration duties.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Dell

Did you find this article useful?
52 out of 97 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:






Related Jobs

Technical Architect (Open Source / Java), Berkshire

Huxley Associates are recruiting for Technical Architects to join an experienced team of technology and consulting professionals with strong ...

Technical Architect (Open Source), Berkshire (optional home working)

My Client, a leading Consulting Company based in Reading is seeking a Technical Architect who is capable of working across multiple projects to join ...

Linux Administrator Redhat, Suse, Debian,Apache, West of London 38k

Linux Administrator Redhat, Suse, Debian, Apache, 38k Linux Systems Administrator (Debian/Ubuntu/MYSQL/Apache/UNIX) is needed by my leading ...

Featured Talkback

So if you upgrade to XP SP3 you can't uninstall Internet Explorer, I'm quite sure I'm having a Deja-vu feeling about MS preventing people from uninstalling Internet Explorer in other Windows products.

By: TheKLF99

Read full story:
Upgraders to XP SP3 warned over IE downgrades

Desktop Management Benchmarking

Test Your Desktop Management Systems

How good are your company's desktop management solutions? How do they compare with those of your peers?

Take two minutes to complete our new Desktop Management and Energy Consumption benchmark, and find out what issues your business needs to focus on.