kernel.org compromised
kernel.org compromised
Posted Sep 1, 2011 18:58 UTC (Thu) by rickmoen (subscriber, #6943)In reply to: kernel.org compromised by raven667
Parent article: kernel.org compromised
As it turned out, the kernel.org regular (not a site admin) who implied that (in a mailing list conversation with me) subsequently allowed as how he really wasn't sure about the signing logic but that he in fact would speculate that the signing doesn't happen on the shared host itself.
Anyway, perhaps we'll hear more-precise details directly from the site admins, when they've caught up on what is doubtless an exhausting (and annoying) cleanup and forensics job and caught some sleep.
I'm already hearing some plausible speculation about how the intruders might have stolen privilege escalation without needing to locally attack software / configurations on kernel.org itself, but let's wait to hear the word from the horse's mouth.
Rick Moen
rick@linuxmafia.com
