ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Desktop platforms Toolkit in association with http://ad.doubleclick.net/clk;205413468;14699245;m?http://adfarm.mediaplex.com/ad/ck/2397-58840-22058-14

Gentoo Linux server compromised

Patrick Gray ZDNet Australia

Published: 04 Dec 2003 11:15 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

A Gentoo Linux project server has been compromised by attackers and subsequently pulled offline for a full forensic analysis.

The attack and subsequent compromise comes after several machines belonging to the Debian Linux project were breached by attackers last month. A forensic analysis of the Debian machines revealed no software packages or source code offered for download were affected -- a claim now being made by Gentoo.

The maintainers of the Gentoo Linux distribution have released a statement which describes the incident. "One of the servers that makes up the rsync.gentoo.org rotation was compromised via a remote exploit," it reads. "The compromised system had both an IDS and a file integrity checker installed and… we are reasonably confident that the portage tree stored on that box was unaffected."

The Gentoo team claim the breach was detected within approximately one hour.

"During this time, approximately 20 users synchronised against the portage mirror stored on this box. The method used to gain access to the box remotely is still under investigation. We will release more details once we have ascertained the cause of the remote exploit," it read.

The machine didn't actually belong to the project. It was donated by a sponsor, whose identity is at this stage undisclosed.

The Debian project servers were compromised by a previously unknown local vulnerability in the Linux kernel which has since been identified and rectified by a patch.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Kyocera

Did you find this article useful?
58 out of 133 people found this useful


Full Talkback thread

0 comments


Company/Topic Alerts

Create a new alert from the list below:



Related Jobs

Database Developers ( SQL / T-SQL / SSIS / ETL) - Chatham Maritime

As and when required, carry out database administration and maintenance tasks including capacity planning, security and integrity planning, index ...

DBA - SQL Server 2005 - London, South East

Test disaster recovery scenarios Performs regular random drills to test the backup plan and to test the integrity of the companys backups. Create ...

Embedded Software Engineer MPEG Video Set Top Box Open GL Digital TV

Top Box, Mobile Phone and Digital Media platforms. Huxley Associates has a new requirement for an Embedded Software Engineer to work on a 6-month ...

Featured Talkback

So if you upgrade to XP SP3 you can't uninstall Internet Explorer, I'm quite sure I'm having a Deja-vu feeling about MS preventing people from uninstalling Internet Explorer in other Windows products.

By: TheKLF99

Read full story:
Upgraders to XP SP3 warned over IE downgrades

Desktop Management Benchmarking

Test Your Desktop Management Systems

How good are your company's desktop management solutions? How do they compare with those of your peers?

Take two minutes to complete our new Desktop Management and Energy Consumption benchmark, and find out what issues your business needs to focus on.