LinuxQuestions.org
Latest LQ Deal: Latest LQ Deals
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 12-01-2010, 06:27 AM   #1
win32sux
LQ Guru
 
Registered: Jul 2003
Location: Los Angeles
Distribution: Ubuntu
Posts: 9,870

Rep: Reputation: 380Reputation: 380Reputation: 380Reputation: 380
Exclamation Savannah GNU Site Compromised


Quote:
A site belonging to the Savannah GNU free software archive was attacked recently, leading to a compromise of encrypted passwords and enabling the attackers to access restricted project material.

The compromise was the result of a SQL injection attack against the savannah.gnu.org site within the last couple of days and the site is still offline now. A notice on the site says that the group has finished the process of restoring all of the data from a clean backup and bringing up access to some resources, but is still in the middle of adjusting its security settings.
Complete Article
 
Old 12-02-2010, 08:36 AM   #2
jens
Senior Member
 
Registered: May 2004
Location: Belgium
Distribution: Debian, Slackware, Fedora
Posts: 1,463

Rep: Reputation: 299Reputation: 299Reputation: 299
Chronological account of the events:
http://www.fsf.org/blogs/sysadmin/sa...u.org-downtime
 
1 members found this post helpful.
Old 12-02-2010, 11:14 AM   #3
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
Without the benefit of insider knowledge, what would you all say we could learn from the account of events as posted there?
 
Old 12-02-2010, 12:40 PM   #4
H_TeXMeX_H
LQ Guru
 
Registered: Oct 2005
Location: $RANDOM
Distribution: slackware64
Posts: 12,928
Blog Entries: 2

Rep: Reputation: 1301Reputation: 1301Reputation: 1301Reputation: 1301Reputation: 1301Reputation: 1301Reputation: 1301Reputation: 1301Reputation: 1301Reputation: 1301
Quote:
Originally Posted by unSpawn View Post
Without the benefit of insider knowledge, what would you all say we could learn from the account of events as posted there?
Well ...

Quote:
# Fri Nov 26 14:27 UTC -- At least one Savannah admin account was compromised by brute forcing the password.
Stronger passwords. (probably the main cause)

Prevent SQL injection, there are plenty of articles on this.

From the rest I sense that many things were not configured properly.
 
Old 12-05-2010, 08:59 AM   #5
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
Indeed. Weak password policy, non-existent or insufficient user input, request and log checking and reporting, lax permissions for the www-cvs user, no use of cron.deny, web server misconfiguration and no probably MAC. Taking nearly three days to get notified of (or do something about) malicious activity is way too long.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Site compromised...htaccess modified bhm8hwcm Linux - Security 2 04-10-2009 09:15 AM
LXer: GNU Consumer Reports (new site) LXer Syndicated Linux News 0 02-19-2008 12:50 AM
LXer: FSF/GNU Project Web Site Overhauls Make Navigation Easier LXer Syndicated Linux News 0 10-16-2007 05:40 AM
LXer: GNU Herds: The Job Site With a Free Software Focus LXer Syndicated Linux News 0 09-27-2007 02:50 PM
LXer: News Site for Source Mage GNU Linux LXer Syndicated Linux News 0 06-06-2007 10:17 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 03:41 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration