Advertisement
Promo

Security threats Toolkit

Debian developers locked out after server hack

Renai LeMay ZDNet Australia

Published: 14 Jul 2006 15:25 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

The Debian GNU/Linux project has locked a number of its developers out of their system accounts following a security scare in which the hack of a key internal server was discovered this week.

The lockout took place due to the fact a compromised developer account was used to take control of the server, according to an email sent to the community by Debian developer Martin Schulze.

"At least one developer account has been compromised a while ago and has been used by an attacker to gain access to the Debian server," Schulze wrote.

The developer said the attacker then used a recently discovered vulnerability in the Linux kernel to gain root — or admin — access on the server.

"An investigation of developer passwords revealed a number of weak passwords whose accounts have been locked in response," Schulze wrote.

While the compromised server — dubbed "gluck" — has had its software reinstalled and is now back online with all services intact, other parts of Debian's infrastructure remain closed off from casual access.

"Other Debian servers have been locked down for further investigation whether they were compromised as well," wrote Schulze. "They will be upgraded to a corrected kernel before they will be unlocked".

Beware
Schulze said the particular Linux vulnerability only exists in kernel versions:

  • 2.6.13 up to versions before 2.6.17.4
  • 2.6.16 up to versions before 2.6.16.24

Schulze advised admins to upgrade their software if they were using these versions but said the current stable version of Debian was not affected as it run kernel 2.6.8.

Wider damage to Debian's infrastructure may have been avoided. "Due to the short window between exploiting the kernel and Debian admins noticing, the attacker hadn't time/inclination to cause much damage," wrote Schulze.

"The only obviously compromised binary was /bin/ping. The compromised account did not have access to any of the restricted Debian hosts. Hence, neither the regular nor the security archive had a chance to be compromised."

The embarrassing security breach is not the first for Debian. In November 2003 several of Debian's servers were similarly compromised and pulled offline.

  • Email
  • Trackback
  • Clip Link
  • Print friendlyPrint with EPSON

Did you find this article useful?
132 out of 212 people found this useful


Full Talkback thread

0 comments


Company/Topic Alerts

Create a new alert from the list below:






Video icon

Video

Sentry Posts Blog

Official Organizations Losing Data

How does this article from earlier today make you feel? How many more government, health service, or military officials are going to lose pen drives, DVDs, USB hard disks and even entire... More

2 comments

Twitter hack was DNS redirect

Twitter has said an attack on Thursday which took the site offline for many users was the result of a DNS redirect. A group calling itself the Iranian Cyber Army redirected users... More

1 comment

McKinnon lawyers seek judicial review

Lawyers seeking a judicial review for Nasa hacker Gary McKinnon lodged fresh evidence of his psychiatric state at the High Court on Thursday. Karen Todner, McKinnon's solicitor,... More

1 comment

Win a BlackBerry with Vlingo voice recognition

Win a BlackBerry with Vlingo voice recognition

What is ZDNet UK's usual tagline?

Competition closes - 14 Jan 2010


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters