Wilders Security Forums  

Go Back   Wilders Security Forums > Software, Hardware and General Services > all things UNIX
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old September 11th, 2011, 02:16 PM
ronjor's Avatar
ronjor ronjor is online now
Global Moderator
 
Join Date: Jul 2003
Location: Texas
Posts: 46,206
Default Security breach at Linux Foundation

Quote:
The Linux Foundation has mailed users of the Linux.com and LinuxFoundation.org sites informing them that they discovered a security breach on 8 September which "may have compromised your username, password, email address and other information". The Foundation says that it believes the breach is connected to the security breach at kernel.org at the start of September.
http://www.h-online.com/security/new...n-1340733.html
  #2  
Old September 11th, 2011, 03:30 PM
J_L's Avatar
J_L J_L is offline
Massive Poster
 
Join Date: Nov 2009
Posts: 4,831
Default Re: Security breach at Linux Foundation

Wow, does that affect the admins as well?
__________________
  #3  
Old September 11th, 2011, 03:39 PM
GrailVanGogh's Avatar
GrailVanGogh GrailVanGogh is offline
Regular Poster
 
Join Date: May 2007
Location: US
Posts: 94
Default Re: Security breach at Linux Foundation

Quote:
Originally Posted by J_L
Wow, does that affect the admins as well?

It would IMO be a smart move for everyone on that site to change their passwords.
  #4  
Old September 12th, 2011, 02:25 PM
fsr fsr is offline
Regular Poster
 
Join Date: Jul 2010
Posts: 190
Default Re: Security breach at Linux Foundation

Linux Foundation Confirms Malware Attack
  #5  
Old September 12th, 2011, 02:28 PM
dw426 dw426 is offline
Massive Poster
 
Join Date: Jan 2007
Posts: 5,543
Default Re: Security breach at Linux Foundation

Quote:
Originally Posted by fsr

What the heck is up with that link? Using Firefox 8, I go to the site and am immediately redirected to the mobile version of it, which doesn't contain the article.
  #6  
Old September 12th, 2011, 02:39 PM
fsr fsr is offline
Regular Poster
 
Join Date: Jul 2010
Posts: 190
Default Re: Security breach at Linux Foundation

Works fine for me. Anyway please don't shoot the messenger.
  #7  
Old September 12th, 2011, 02:42 PM
dw426 dw426 is offline
Massive Poster
 
Join Date: Jan 2007
Posts: 5,543
Default Re: Security breach at Linux Foundation

Quote:
Originally Posted by fsr
Works fine for me. Anyway please don't shoot the messenger.

Lol, not shooting at you. I've just not seen that happen on FF before
  #8  
Old September 12th, 2011, 03:45 PM
fsr fsr is offline
Regular Poster
 
Join Date: Jul 2010
Posts: 190
Default Re: Security breach at Linux Foundation

Linux Foundation has just issued an update,
Quote:
*** UPDATE***

We want to thank you for your questions and your support. We hope this FAQ can help address some of your inquiries.

Q: When will Linux Foundation services, such as events, training and Linux.com be back online?

Our team is working around the clock to restore these important services. We are working with authorities and exercising both extreme caution and diligence. Services will begin coming back online in the coming days and will keep you informed every step of the way.

Q: Were passwords stored in plaintext?

The Linux Foundation does not store passwords in plaintext. However an attacker with access to stored password would have direct access to conduct a brute force attack. An in-depth analysis of direct-access brute forcing, as it relates to password strength, can be read at http://www.schneier.com/blog/archive...ng_secure.html. We encourage you to use extreme caution, as is the case in any security breach, and discontinue the use of that password if you re-use it across other sites.

Q: Does my Linux.com email address work?

Yes, Linux.com email addresses are working and safe to use.

Q: What do you know about the source of the attack?

We are aggressively investigating the source of the attack. Unfortunately, we can't elaborate on this for the time being.

Q: Is there anything I can do to help?

We want to thank everyone who has expressed their support while we address this breach. We ask you to be patient as we do everything possible to restore services as quickly as possible.
http://www.linux.com/
  #9  
Old September 13th, 2011, 03:22 AM
PJC PJC is offline
Very Frequent Poster
 
Join Date: Feb 2010
Location: Internet
Posts: 2,962
Default Security breach at Linux Foundation

Linux world in security spinout as Linux Foundation and Kernel.org remain "temporarily unavailable"
  #10  
Old September 15th, 2011, 11:50 PM
Gullible Jones
 
Posts: n/a
Default Re: Security breach at Linux Foundation

Just FWIW, Linux kernel development has moved to GitHub, so the source code still flows: https://github.com/torvalds/linux
  #11  
Old September 19th, 2011, 09:22 AM
tlu's Avatar
tlu tlu is offline
Very Frequent Poster
 
Join Date: Sep 2004
Posts: 2,066
Default Re: Security breach at Linux Foundation

And here is why one should not worry about the integrity of the kernel source after this incident.
 

Wilders Security Forums > Software, Hardware and General Services > all things UNIX « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 03:16 PM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums