LWN.net Logo

It may not be "bad" developers

It may not be "bad" developers

Posted Dec 4, 2003 3:06 UTC (Thu) by Ross (subscriber, #4065)
In reply to: Savanna.gnu.org compromised too by QuisUtDeus
Parent article: Savanna.gnu.org compromised too

It may not have been the developer's fault. I'm pretty sure that in the
Debian incident the developer's account was being used by someone else
who had sniffed his or her password. Maybe the intruder(s) compromized a
bunch of desktops and has been collecting passwords?

I also remember that the FSF's ftp site was compromized by an "inside"
job a few months back... or maybe it was the Savanna server after all.
My memory isn't that wonderful.


(Log in to post comments)

It may not be "bad" developers

Posted Dec 4, 2003 4:01 UTC (Thu) by piman (subscriber, #8957) [Link]

This is the case with Debian; a developer's home system (or one of his/her home systems) had been compromised, and so the attacker got the password (or phrase) when she/he logged into a Debian server.

Copyright © 2012, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds