LWN.net Logo

Advertisement

Fast storage & processing: iSCSI, NFS, SMB/CIFS, clusters for financial, media, HPC, research, virtualization

Advertise here

Debian's Alioth cracked

Anybody having trouble getting through to the Debian Alioth web server now knows why: the system was broken into by way of a pmwiki vulnerability. "This security alert is over, however we have way too many projects running some custom-installed web applications. We're going to review everything that is installed and come up with suggestion to use the packaged (and thus security-supported) version of the web applications when possible."

It has now been decided that the new Alioth will be hosted in a Xen client. "This means it's easy to stop (or shutdown) the Alioth host for inspection, or to simply reinstall it from scratch. That's why while preparing the new Alioth, I'm documenting the configuration of all the services."


(Log in to post comments)

Copyright © 2006, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds