Gentoo Offline due to Security FlawBest Security Tips offers daily news, information, advices and tips about spyware, adware, viruses, trojans, web vulnerabilities, hackers, other threats    | Register now | Login
   
TIPS NEWS TOOLS DOWNLOADS MALWARE FORUM BOOKS FREE MAGAZINES FREE WEBCASTS & VIDEOS
GFI LANguard Network Security Scanner - Dld 30-day trial! del.icio.us  digg  Furl  NewsVine  Spurl  Blinklist  Ma.gnolia  Reddit  Tailrank  YahooMyWeb 
Best Tips
Security Scanner
Security Categories
Advertise With Us!
Latest Viruses / Threats
Downloads
RSS / Atom Feeds
Linux Security : Gentoo Offline due to Security Flaw
Posted by Max on 2007/9/27 12:35:00 (513 reads)
Linux Security

The Gentoo Project was forced to pull the plug on major section of it’s website as soon as they found out that the systems were vulnerable to a command injection attack. This vulnerability might let an attacker remotely execute commands on the compromised servers.

Many users trying to access Gentoo Archives and other 7 areas of gentoo.org are welcomed with a message of unavailability. The Gentoo administrators were urged to take the servers offline in order to prevent further exploits and to allow forensic analysis.

The words "further exploitation" and "forensic analysis" suggest the server was pwned, but Gentoo assures us the damage was minimal.

"There was no possibility of any leak of personal or meddling with the Gentoo Portage tree," Mike Doty, a member of Gentoo's Infrastructure team, said in an emailed statement. "The attack was limited to one service on one server."

Members intend to rebuild the server and will also perform a security audit on source code for packages.gentoo.org, which is the service containing the injection vulnerability. According to this advisory, the vulnerability allows the remote execution of code by attaching a semicolon to the end of the URL, immediately followed by the command an attacker wants to run. The bottom of the page will then display the output of that command.

Gentoo's advisory comes a week after Ubuntu unplugged five of its eight production servers following the discovery they had been so badly compromised that they were being used to attack other sites. Turns out the systems, which were sponsored by Canonical and hosted by the community, were running an old version of Ubuntu.

Other Gentoo sites and services being shuttered included packagestest.gentoo.org, scripts.gentoo.org, archivestest.gentoo.org, kiss.gentoo.org, stats.gentoo.org and survey.gentoo.org. Gentoo wouldn't estimate when it will have them back online.




Other articles
2008/9/3 17:16:33 - New Spam Terrier 2.0! Free, easy-to-use spam protection
2008/9/3 17:06:53 - New Kaspersky Internet Security 2009 Release
2008/9/3 16:57:16 - New Proactive Security-ware XenCare SoftLock 2.0
2008/9/1 17:00:07 - Sex, Drugs and Software Boost Spam Succes Rate
2008/9/1 16:51:15 - New Digipass Go 7 Strong User Authentication From VASCO

The comments are owned by the poster. We aren't responsible for their content.