Free Software Foundation's software repository hacked
- 02 December, 2010 05:25
The Web front end for a Free Software Foundation software repository remains down after the server it was hosted on was attacked last week.
The repository holds the pages for the organization's Gnu.org website, which the attackers altered last weekend. They also downloaded all the user names and encrypted passwords. None of the Gnu software projects on the server have been compromised as part of the attack, said Matt Lee, FSF's campaign manager.
As a precaution, the Savannah server's administrators eliminated any changes to the server contents since Nov. 23, a day before the first attack. Developers using the repositories can upload changes from their local copies, and as they are signed onto the system, they will be required to change their password.
According to the FSF, attackers breached the FSF server Nov. 24 by using SQL injection attacks against the Savane bug tracking application. The Savannah server, maintained by volunteers, holds the contents of the Gnu.org website in a CVS repository, as well as the Gnu-sponsored software projects. The server hosts both the gnu.savannah.gnu.org and savannah.nongnu.org domains, both of which are used to access the repositories.
The attackers obtained the user names and hashed passwords from a MySQL database and were able to create at least one new administrative account for the website, which allowed them to deface the Gnu.org home page.
The attackers also found a directory with PHP write access and ran a PHP reverse shell procedure to run root kits against the server. At this point however, the FSF believes they did not get root access to the server itself.
Savane is being rewritten and the developers are fixing the vulnerability, Lee said.
The FSF is not the only open-source software organization whose repositories have been compromised. Earlier this year, the Apache Software Foundation also had its site and passwords compromised.
Join the CIO Australia group on LinkedIn. The group is open to CIOs, IT Directors, COOs, CTOs and senior IT managers.
- OAIC releases privacy impact assessment guide for consultation
- Some Australian businesses 'unlikely' to be ready for Privacy Act changes: survey
- BYOA 'shadow IT' grows in the enterprise: Telsyte
- Cost of a Privacy Act breach could extend to ongoing audits: legal expert
- How Hunter Water is saving $50k a year in software licences
Trust issue looms large for tech companies capitalizing on personal data
5 women who've made it in IT
Five trends affecting legal CIOs
CIO Roundtable: The changing face of security
Bitcoin malware count soars as cryptocurrency value climbs
‘A Little Extra Service’ Raises Customer Satisfaction and Lowers Costs
Companies are responding to the digital generation’s preference for online support, with new channels like Live Chat and Email Management. These mobile-friendly solutions give customers the right answers at the right time, when self-service just isn’t enough, and phone calls are undesirable. Read about these new touch points and the importance of a personalized web self-service.
Protection Storage Architecture: The What, Why, and How
Traditional backup architectures lack the flexibility, agility, and scale to meet new data protection challenges and requirements. That’s where a Protection Storage Architecture comes in. This whitepaper details how transformational architecture enables backup teams to solve immediate tactical challenges, while helping to evolve IT teams.
451 Group Research Report MDM Trends
As the BYOD model continues to grow at twice the rate of corporate-owned devices, enterprises are facing an increasingly diversified mobility landscape. And though BYOD brings many benefits, complex management and security challenges are also ushered in. Read this report to understand what MDM can and cannot do for you and which solutions are being chosen today - and tomorrow.