LinuxQuestions.org
Visit Jeremy's Blog.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 08-24-2008, 04:12 AM   #1
win32sux
LQ Guru
 
Registered: Jul 2003
Location: Los Angeles
Distribution: Ubuntu
Posts: 9,870

Rep: Reputation: 380Reputation: 380Reputation: 380Reputation: 380
Exclamation WARN: Red Hat Update for Tampered OpenSSH Packages


Quote:
Description:
Red Hat has issued an update for openssh, which corrects a small number of OpenSSH packages that have been tampered with.

Some packages have been signed during an intrusion incident on the Red Hat computer systems. The vendor is still investigating the incident.

An issue that prevents ssh from using a trusted X11 cookie if creation of an untrusted cookie fails has also been corrected.

Solution:
Updated packages are available via Red Hat Network.
Secunia Advisory | CVE-2007-4752

You can read about this security breach on several sites, such as The Register, CNET News, and SecurityFocus.

Red Hat, Inc. has set up an informational page for its users here.

Last edited by win32sux; 08-24-2008 at 04:19 AM.
 
Old 08-24-2008, 06:18 PM   #2
xnomad
Member
 
Registered: Jun 2005
Posts: 53

Rep: Reputation: 15
Red Hat security breach, why sign the packages

Hi,

Just a quick question. During the recent intrusion on the Red Hat systems the intruder signed some of the packages. What's the motivation behind that? Surely a different PGP signature is going to alert people installing that package with yum?
 
Old 08-24-2008, 06:34 PM   #3
pinniped
Senior Member
 
Registered: May 2008
Location: planet earth
Distribution: Debian
Posts: 1,732

Rep: Reputation: 50
Who knows - it could be someone breaking in and signing for bragging rights. Then again, people often ignore warnings if they believe the software is from a trusted source. When I play around with Debian archives I often get a "signature cannot be verified" and I can choose to ignore that, or else update my key file and try again. So if someone cracked the Debian servers and changed the archive keyring as well as signed some packages, if someone updated from the bad keyring then they could install bad packages without ever knowing.
 
Old 08-24-2008, 06:45 PM   #4
win32sux
LQ Guru
 
Registered: Jul 2003
Location: Los Angeles
Distribution: Ubuntu
Posts: 9,870

Original Poster
Rep: Reputation: 380Reputation: 380Reputation: 380Reputation: 380
I moved your posts into this thread in order to keep the discussion in one place.
 
Old 08-24-2008, 09:06 PM   #5
chort
Senior Member
 
Registered: Jul 2003
Location: Silicon Valley, USA
Distribution: OpenBSD 4.6, OS X 10.6.2, CentOS 4 & 5
Posts: 3,660

Rep: Reputation: 76
Quote:
Originally Posted by xnomad View Post
Hi,

Just a quick question. During the recent intrusion on the Red Hat systems the intruder signed some of the packages. What's the motivation behind that? Surely a different PGP signature is going to alert people installing that package with yum?
They were apparently able to use Red Hat's signing key.
 
Old 08-25-2008, 08:55 PM   #6
win32sux
LQ Guru
 
Registered: Jul 2003
Location: Los Angeles
Distribution: Ubuntu
Posts: 9,870

Original Poster
Rep: Reputation: 380Reputation: 380Reputation: 380Reputation: 380
Hopefully once Red Hat, Inc. has completed its forensic analysis they will provide us with some details as to what exactly happened (and what they are doing to prevent it from happening again). I've been monitoring the news and haven't seen anything of that sort yet, though. And the Red Hat website is still down for "planned maintenance".
Quote:
We are currently performing routine systems maintenance and our on-line systems are temporarily unavailable. We apologize for this inconvenience, and we will work with you over the phone to help. Please call us at the numbers below or try your web request again later.
My guess is that the Fedora Project will come clean first, though.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Red Hat Enterprise Linux v.3 update 5 to update 6 kalif76 Red Hat 0 07-28-2008 06:12 AM
Red Hat Update Agent freezing, unable to update (FC4) Malakye Fedora 1 12-09-2005 08:02 PM
Red Hat 9: Is it safe to update glib2,pango... via synaptic with fedora packages? gevero Linux - Software 0 03-17-2005 04:11 AM
Red Hat AS 3 Update 3 conflict with Openssh-3.9p1 !!?? jiawj Red Hat 0 09-13-2004 08:43 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 04:00 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration