Debian development server compromise



Sans also brings this story about the Debian development server being compromised. Investigation is ongoing. The machine was gluck.debian.org and hosted CVS among other things (ddtp, lintian, people, popcon, planet, ports, release). It has been taken offline currently for a reinstall, other systems have been locked down until they can patch the vulnerability that they suspect was exploited. More details will be announced.


An update that I’ve seen today is that apparently a developer account with a weak password was compromised. Then the attacker used a LOCAL vulnerability to escalate privileges. The lesson to be learned here is that no matter how secure your network services are, the soft underbelly is the list of users that can log in to the machine (if that’s allowed.) I mean…. if you have a tight ssh config and let bob@yourmachine.com use “bob” for his password…. good luck.

Network facing services deserve HARD passwords. One of the best suggestions I’ve heard for creating hard passwords that can be more easily remembered….. Think of a sentence, use the first letter of each word, substituting numbers in where possible. For instance…. “Look Before you Leap” would become… Lb4YL this is fairly short, but better than “look” It’s also suggested to vary the case (upper/lower).

Related Posts

Blog Traffic Exchange Related Posts
  • Network Security guide for the home or small business network - Part 6 - Secure your services This one is going to be tougher. Of what we've looked at so far this will probably take more work and learning than any of the others. The good news is, depending on your situation you may need to do less here. IF you have decided that your pc (or......
  • Blackberry vulnerability to be released soon Between the Lines is warning that Blackberry Enterprise servers ought to be placed in the DMZ (if not already.) There is word that a critical vulnerability will be announced on August 14th. (And if we already know that's coming then SOMEONE knows what that vulnerability is.) It basically uses software......
  • 5198 Security Vulnerabilities tracked by US-CERT in 2005 The headline probably says most all... 5198 vulnerabilities tracked by US-Cert in 2005. This comes from The SecurityFix. It's probably not every vulernability that was out in 2005, just those that US-CERT issued advisories for. The breakdown is 812 in Windows 2,328 in various Unix/Linux/Mac/BSD systems and 2,058 affecting multiple......
Blog Traffic Exchange Related Websites
  • How to use Twitter, the right way~ Twitter has become so saturated with spammers and scammers over the past year or so that really learning how to use Twitter with the intention of converting some of the traffic it sends has become a false hope. Enter the #internetmarketing hastag into search.twitter.com for instance, and you'll immediately......
  • Umm.. Who Said PPC Is Evil? - Internet Marketing Strategies   Everywhere you look these days, anyone and everyone in Internet Marketing is flocking to "free", "free" and only "free" traffic generation strategies. Article Marketing, Blog Commenting, Forum Participation, Trackbacks, you name it; Somehow almost everyone is under the mistaken impression that "free" is the way to go. So......
  • Oh For Crying Out Loud.. - Internet Marketing Strategies Redefined If the alchemists from the middle ages saw what's going on in the Internet Marketing space today, that is exactly what they'd have to say: "Oh for crying out loud.. What were we thinking when we were hard at work trying to come up with a formula to turn......
en.pdf24.org    Send article as PDF   

Similar Posts


See what happened this day in history from either BBC Wikipedia
Search:
Keywords:
Amazon Logo

Comments are closed.


Switch to our mobile site