LinuxQuestions.org
Share your knowledge at the LQ Wiki.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 04-03-2009, 09:46 PM   #1
mazinoz
Member
 
Registered: Mar 2003
Location: Mansfield Queensland Australia
Distribution: Linux Mint - Tara
Posts: 497

Rep: Reputation: 35
Exclamation www.aarnet.edu.au Centos5.3 mirror ISO corruption?


Dear Moderator

Could you please check this out and post in relevant forums.

A quick comparison will show a suspicious DVD .iso file dated 1st April 2009 on the aarnet.edu.au server. I downloaded but didn't open the file and trashed and deleted it immediately, so I don't know what the payload if any is. I did notice my modem disconnecting a few times, but that may have been my ISP. Chkrootkit and rkhunter are ok, this morning.

This is not a joke, just think people should be aware. I don't know if other servers for Centos mirrors have been affected or not. Could not find anything about this on centos.org or googling.

Cheers and best wishes

Mazinoz

Last edited by mazinoz; 07-19-2009 at 07:07 PM.
 
Old 04-03-2009, 10:25 PM   #2
AlucardZero
Senior Member
 
Registered: May 2006
Location: USA
Distribution: Debian
Posts: 4,824

Rep: Reputation: 615Reputation: 615Reputation: 615Reputation: 615Reputation: 615Reputation: 615
so.. why are you telling us and not www.aarnet.edu.au?
 
Old 04-03-2009, 10:27 PM   #3
billymayday
LQ Guru
 
Registered: Mar 2006
Location: Sydney, Australia
Distribution: Fedora, CentOS, OpenSuse, Slack, Gentoo, Debian, Arch, PCBSD
Posts: 6,678

Rep: Reputation: 122Reputation: 122
Interestingly AARNET took a long time to update whe n5.3 came out. I ended up using base URLs in yum since there was no sign that a 5.3 directory was being created. This was probably 6 hours post release. Maybe things just got screwed up.
 
Old 04-03-2009, 10:40 PM   #4
mazinoz
Member
 
Registered: Mar 2003
Location: Mansfield Queensland Australia
Distribution: Linux Mint - Tara
Posts: 497

Original Poster
Rep: Reputation: 35
Quote:
Originally Posted by AlucardZero View Post
so.. why are you telling us and not www.aarnet.edu.au?
I already have notified aarnet.edu.au, but maybe their webmaster isn't in today?, also centos.org and aussie.hq.centos.org. so get your facts right before you have another go at me!
 
Old 04-04-2009, 03:59 AM   #5
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
Please don't.

As ISO D/L's have a SHA1 or MD5sum it would be easy to check if your DL was corrupted. Since you deleted the ISO you have no indication, and thus no reason, to shout wolf. Please don't tell us something is hacked unless you have some proof to show. If you have no means to check, then next time please use a less sensationalist thread title. LQ and the Linux Security forum will value quality of content over instant satisfaction or slashdotting any time. I'm gonna moderate this thread title to reflect the current situation. Thanks for understanding.

Last edited by unSpawn; 04-04-2009 at 04:03 AM. Reason: clarity
 
Old 04-04-2009, 05:19 AM   #6
billymayday
LQ Guru
 
Registered: Mar 2006
Location: Sydney, Australia
Distribution: Fedora, CentOS, OpenSuse, Slack, Gentoo, Debian, Arch, PCBSD
Posts: 6,678

Rep: Reputation: 122Reputation: 122
I guess the suspicion was because of the differing iso sizes.
 
Old 04-04-2009, 07:34 AM   #7
AlucardZero
Senior Member
 
Registered: May 2006
Location: USA
Distribution: Debian
Posts: 4,824

Rep: Reputation: 615Reputation: 615Reputation: 615Reputation: 615Reputation: 615Reputation: 615
Quote:
Originally Posted by mazinoz View Post
I already have notified aarnet.edu.au, but maybe their webmaster isn't in today?, also centos.org and aussie.hq.centos.org. so get your facts right before you have another go at me!
Sorry - left my mind reading hat at home again.
 
Old 04-04-2009, 07:38 AM   #8
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
Quote:
Originally Posted by billymayday View Post
I guess the suspicion was because of the differing iso sizes.
Exactly the reason for my response: next to fish vs fishing rod issues, in this forum we should always aim to provide clarity not FUD or guesstimations.
 
Old 04-21-2009, 08:41 PM   #9
mazinoz
Member
 
Registered: Mar 2003
Location: Mansfield Queensland Australia
Distribution: Linux Mint - Tara
Posts: 497

Original Poster
Rep: Reputation: 35
Wink

Quote:
Originally Posted by unSpawn View Post
As ISO D/L's have a SHA1 or MD5sum it would be easy to check if your DL was corrupted. Since you deleted the ISO you have no indication, and thus no reason, to shout wolf. Please don't tell us something is hacked unless you have some proof to show. If you have no means to check, then next time please use a less sensationalist thread title. LQ and the Linux Security forum will value quality of content over instant satisfaction or slashdotting any time. I'm gonna moderate this thread title to reflect the current situation. Thanks for understanding.
My apologies if I was unclear, I thought pictures would explain the situation adequately. I don't have the luxury of a crash-test dummy machine at home. I was suspicious because of the similar sizes, except one was Mb and the other Gb, the date 1st April 2009, and because 37Mb was a bit small for a DVD iso. I thought I posted a ? on my title, implying that my statement was a question. I guess it was sensationalist, but I wanted to know if other people had more info about the situation, and I wanted to know urgently if they had been hacked or not. 'Hacking' or a 'joke' were the only terms I could think of at the time. I also just wanted to alert people to be wary until the matter was clarified.

[B]Some time later[/B] the web admin at aarnet.edu.au emailed me that it was just a failed download. I just thought it odd that they hadn't noticed the situation themselves and remedied it if that were the case, especially from an organisation like aarnet.edu.au.

Anyway the site is up again with an amended DVD iso.

I do appreciate your info on security issues. Guess I was just a bit paranoid this time.

Cheers
 
Old 04-22-2009, 04:18 PM   #10
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
Quote:
Originally Posted by mazinoz View Post
I do appreciate your info on security issues. Guess I was just a bit paranoid this time.
No problem. I agree we should trust mirrors to be and keep up to date and check what they mirror. However that does not exempt individuals from checking their downloads themselves because they have the means to verify things are OK. It's a good thread in that I hope it will remind people to actually check things, communicate and investigate things. Thanks for the feedback.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
aarnet.edu.au Centos 5.3 mirror hacked. mazinoz Linux - Server 1 04-04-2009 05:23 PM
10.2 ISO corruption when using FDM and Multiple Mirrors beyboo Slackware 3 12-28-2005 12:23 PM
www mirror: is dnotify / rsync my best bet? GuitsBoy Linux - Software 2 01-27-2004 07:34 PM
Slackware 8.1 ISO mirror? SlCKB0Y Slackware 11 06-20-2002 01:47 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 08:47 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration