Debian Investigation Report
Posted Dec 2, 2003 17:59 UTC (Tue) by
piman (subscriber, #8957)
In reply to:
Debian Investigation Report by utidjian
Parent article:
Debian Investigation Report
Please read it again. Only one password was sniffed. Likely, a developer's home machine was compromised (probably with the same rootkit), and they logged into a Debian server.
Once the attack had that password (or passphrase + private key, whatever), they can log into many Debian machines. From there, they used the brk vulnerability to get root, and then, install SuckIt.
(
Log in to post comments)