LWN.net Logo

Numerous Debian Project systems compromised

Numerous Debian Project systems compromised

Posted Nov 21, 2003 23:19 UTC (Fri) by Ross (subscriber, #4065)
In reply to: Numerous Debian Project systems compromised by JoeBuck
Parent article: Numerous Debian Project systems compromised

This is interesting. I would like to know what mechanism was used to
either gain unauthorized remote access to the system or to escalate from
an authorized level of access to an unauthorized one.

Is it something that can prevented by better hardening of the servers?
Was it due to unapplied patches or misconfiguration? Bad passwords?
GPG bugs? Compromized systems which were trusted by the server?

I also wonder if there is any connection with the recent modification of
the Linux CVS gateway.

I think we can better protect ourselves in the future if we understand
how these attacks are being perpetrated.


(Log in to post comments)

Copyright © 2008, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds