Server breach raises Linux code worries

A key server housing software used in Linux and other projects was open to an attacker for four months, creating fears that source code was compromised.

The GNU Project, which develops many of the components in the Linux operating system, said this week that the system housing its primary download servers has been compromised by an attacker. The project urged those who have downloaded software from the server since March to check that the source code has not been tampered with.

Linux, an open-source operating system that dominates the Web server market, uses the compiler, libraries and other software that was originally developed by the GNU project. The project warned that the attacker may have inserted malicious code into its software, although it said all the code checked so far appeared to be intact.

In an alert issued on Wednesday, computer security response organisation CERT warned that the breach could prove to be a serious problem. "Because this system serves as a centralised archive of popular software, the insertion of malicious code into the distributed software is a serious threat," the warning stated.

The Free Software Foundation, the GNU project's overseer, has issued lists of hashes -- numbers generated by the source code of software known not to have been compromised -- which can be used to verify downloaded code. The lists can be found here and here.

The attacker compromised the project's servers to the root level, gaining complete control over the system, according to the GNU Project. The attack was carried out using an exploit that was revealed on 17 March, and for which a patch only became available a week later. During that week, the intruder compromised the system and installed a piece of malicious code known as a Trojan horse, according to evidence found on the machine.

The Trojan stayed in place until it was discovered in the last week of July, the project said. "The modus operandi of the cracker shows that (s)he was interested primarily in using gnuftp to collect passwords and as a launching point to attack other machines," the project said in a statement on its Web site.

The group said it has spent the weeks since the compromise was discovered verifying the integrity of its software. "Most of this work is done, and the remaining work is primarily for files that were uploaded since early 2003, as our backups from that period could also theoretically be compromised," the statement said.

The project said it believes no source code was compromised. "The evidence includes the MO of the cracker, the fact that every file we've checked so far isn't compromised, and that searches for standard source Trojans turned up nothing," the group stated.

Like this article? Click below to send it to your mobile for free!

Advertisement

Talkback 3 comments

  1. No need for serious concern. The following is the analysis of this incident from CERT: "no source code distributions are believed to have been maliciously modified at this time" https://lwn.net/Articles/44402/ Anonymous -- 15/08/03

    No need for serious concern. The following is the analysis of this incident from CERT:

    "no source code distributions are believed to have been maliciously modified at this time"

    https://lwn.net/Articles/44402/

  2. The most damaging aspect of this breach is the reputation of one of the most popular sources of open source code on the internet. While you can agree that there appears to be little or no risk that code was manipulated in any way, the fact that Sir Scrotum -- 15/08/03

    The most damaging aspect of this breach is the reputation of one of the most popular sources of open source code on the internet.

    While you can agree that there appears to be little or no risk that code was manipulated in any way, the fact that it took a week before the server was patched in the first place would raise eyebrows and increase concerns for anyone contemplating moving to the open source platform.

    It could be argued that if a Microsoft server had been compromised for this period of time, that every Linux or open source advicate would screaming blue murder and saying this was another reason to move to open source.

    Microsoft servers have been compromised in the past - detection of the trojan or hack is usually measured within hours however, and I seem to recall immediately the open source crowd was screaming away back then. Strangly quiet today however. Most I have heard so far is - its OK, no damage done. Server was hacked for 4 months, but its all OK!

  3. Good point, Sir Scrotum... Smacks of hypocracy if you ask me. Anonymous -- 15/08/03

    Good point, Sir Scrotum... Smacks of hypocracy if you ask me.

Add your opinion


Sponsored content

Power Centre - Content from our premier sponsors

Blogs

  • David Braue Telstra's BT coat doesn't fit
    The vision of the future BT portrayed this week at an Australian conference was so far removed from how Telstra's David Quilty has described the British telco that I wonder if they were talking about the same UK.
  • Array Australian security: the lucky country
    Does anyone seriously believe that Australian businesses and government agencies manage security any better than the US or UK?
  • Array Storage infrastructure on the tender track
    For a large-scale storage project, it's not uncommon to go out to tender for the best deal — but when was the last time you had to put together a tender for a document management room?
  • More blogs »

Tags

Back to top

Featured