Linux download site hacked

By Patrick Gray
14 November 2002 04:20 PM
Tags: hack, software, cert, verify, encourage, authenticity, trojan horse, advisory
The download site for two very common Linux based utilities, tcpdump.org, was hacked into on the 11th of this month, and the software available for download was modified to contain Trojan Horse code.

This Trojan Horse, or "back door" software allows the hacker that wrote it to access any machine on which the modified software is run.

The two software items affected are tcpdump and libpcap, tools commonly used in information security applications. Some Intrusion Detection System (IDS) software requires libpcap.

This is the most recent in a string of similar attacks. Sendmail, one of the most widely used email server software packages, was also "trojaned" recently. Others affected in recent months have included OpenSSH, the secure remote access software, and even Fragroute, a hacker utility.

The identity of the hacker conducting this campaign is unknown, as is whether a connection exists between the separate incidents.

CERT have released an advisory in which they ".encourage sites using libpcap and tcpdump to verify the authenticity of their distribution, regardless of where it was obtained."

CERT have provided the information necessary to determine the authenticity of any libpcap or tcpdump software recently downloaded. The advisory also encourages users to verify all software before installing it. "As a matter of good security practice, the CERT/CC encourages users to verify, whenever possible, the integrity of downloaded software."

Advertisement

Talkback 8 comments

    "Linux download site hack ...Anonymous -- 15/11/02

    "Linux download site hacked"

    Wow! This sounds serious! I wonder how many people downloaded linux from this site and now have an infected operating system. I guess it's back to windows for everyone now. That's too bad, it seemed like linux had such promise. Good reporting and even better editorial choice on the headline. Thanks for keeping us so well informed.

    No news "Windows download ...Whats New -- 15/11/02

    No news "Windows download site hacked"

    Of course we don't see articles entitled "Windows download site hacked".

    People would say what's new...

    It takes a third party "h ...MrDamage -- 15/11/02

    It takes a third party "hacker" to compromise anbd trojan Linus systems.

    Windows is designed with Trojans in mind.

    I still know which one is safer.
    (Hint: its the cheaper one)

    this is just typical of one of ...Anonymous -- 28/11/02

    this is just typical of one of microsoft's greatest
    shills-ZDNET. tcpdump is not a part of the linux operating system and is not tied to it.
    it is a general utility that can be used on any variety of unix and probably other OS's
    and was in fact originally written by researchers
    connected to the US gov.the attempt to make it appear that
    the inadequacies of this INDEPENDENTLY PRODUCED
    software is indicative of problems solely with linux
    is the type of FUD that ZDNET has spread on behalf
    of it's pals at Microsoft...who seem radically bugged that
    linux is now hurting MS's market. NICE TRY..ZDNET.

    Re Linux Download Site by Kirk ...Tim Post -- 29/11/02

    Re Linux Download Site by Kirk

    Kirk -

    None of these applications are included, endorsed by or used in the linux installation package. These are third party (some closed source) add ons. All readers please take note that the inherent security of the *nix operating system was not in any compromised (except by nit-wits that used closed source ssl applications, or don't build their own once downloaded). You can thank your pals at Microsoft for even seeing these appear on the market :)

    RE Linux is over rated So.. le ...Tim Post -- 29/11/02

    RE Linux is over rated

    So.. let me guess. You're still using OS/2 Warp?

    Re: Linux is over rated. . . & ...Buck Henry -- 30/11/02

    Re: Linux is over rated. . .

    "So. .let me guess. You're still using OS/2 Warp?"

    Since you asked. . .Yes, I am! Well, only at work, to be honest. I'm using eComStation on my home machines and my notebook.

    While I agree with the first poster that Linux is over rated, I have to point out that it is not nearly as over rated as Windows. . .When was the last time anyone dropped $.5 billion on marketing Linux?And what is marketing? Glad you asked! It is a tool to get your product rated more highly by public opinion than it deserves based upon its technical merits. When people think your product is better than it actually is, then your product is over rated. Windows is the all-time, undisputed champion here!

Add your opinion

Latest Videos

Sponsored content

Power Centre - Content from our premier sponsors

Blogs

  • Suzanne Tindal Sick of broken tender sites
    Some of the state governments desperately need to invest in more user-friendly tender sites so that looking for information on government tenders doesn't have to be a game of blind man's bluff.
  • Array Cyberwar: What is it good for?
    In this week's episode, Cyberwar. What is Australia's place in the world of digital warfare? What are the implications for the NBN?
  • Array Is wholesale-only backhaul just a pipedream?
    The potential acquisition of Pipe Networks by SP Telemedia has raised the question about whether vertically integrated backhaul providers will mean higher wholesale prices for ISP customers.
  • More blogs »

Tags

Back to top

Featured