Home · Compatibility Lists · Support Forums · FAQ · News Archive · Articles · Submit News/Upcoming News
Linux Compatible
advertisement


Security Notice: Attempted Break-In on www.centos.org
Posted by Philipp on: 2009-07-04 04:31:52 [ Print | Permalink ]

A security notice from the CentOS project:

"Dear Users,

on Friday evening, July 3rd (UTC) we found a few suspicious files on the CentOS webserver. Upon investigating we found out that the files had been put there through Xoops (the CMS www.centos.org runs on) - and that this was possible due to a an administrative error which has been corrected.

As far as we can see there has been no data or binary injected into the system or taken from the system. The machine hasn't been used as a source for sending spam (in the widest possible meaning) either.


We have been able to identify the source of the attacks, but have not been able to find out if the files have been put there through a compromised user account in the Xoops system.

Although we are fairly sure that there has been no such compromise, we have enforced a password expiry on all accounts on the system.

wiki.centos.org and bugs.centos.org - though being on the same machine - have not been affected by this.

All users having an account on www.centos.org need to acquire a new password through the "lost password" system of Xoops.

We are terribly sorry for any inconvenience this might cause you and would like to apologize for that.

On behalf of the CentOS team,

Ralph Angenendt"


Digg it! Slashdot Del.icio.us Technorati Fark it! Binklist Furl Newsvine Windows Live Netscape Google Bookmarks Reddit! LinkaGoGo Tailrank Wink Dzone Simpy Spurl Yahoo! MyWeb NetVouz RawSugar Smarking Scuttle Magnolia BlogMarks Nowpublic FeedMeLinks Wists Onlywire Connotia Shadows Co.mments
News Source: Email

Related Stories RSS

- CESA-2009:0057 Important CentOS 4 x86_64 squirrelmail security (01/24/2009 11:35 am)
- CESA-2009:0057 Important CentOS 4 i386 squirrelmail security update (01/24/2009 11:34 am)
- CESA-2009:0004 Important CentOS 4 x86_64 openssl security update (01/24/2009 11:32 am)
- CESA-2009:0004 Important CentOS 4 i386 openssl security update (01/24/2009 11:32 am)
- CESA-2009:0010 Moderate CentOS 3 x86_64 squirrelmail - security update (01/12/2009 04:36 pm)
- CESA-2009:0010 Moderate CentOS 3 i386 squirrelmail - security update (01/12/2009 04:35 pm)
- CESA-2008:0978 Critical CentOS 4 s390(x) firefox - security update (11/26/2008 10:48 pm)
- CESA-2008:0617 Moderate CentOS 4 s390(x) vim - security update (11/26/2008 07:14 pm)
- CESA-2008:0976 Moderate CentOS 4 ia64 thunderbird - security update (11/26/2008 07:14 pm)
- CESA-2008:0977 Critical CentOS 4 ia64 seamonkey - security update (11/26/2008 07:12 pm)
- CESA-2008:0978 Critical CentOS 4 ia64 firefox - security update (11/26/2008 09:34 am)
- CESA-2008:0972 Important CentOS 4 s390(x) kernel - security update (11/26/2008 09:34 am)
- CESA-2008:0618-01: Moderate CentOS 2 i386 vim security update (11/26/2008 09:33 am)
- CESA-2008:0972 Important CentOS 4 ia64 kernel - security update (11/26/2008 09:33 am)
- CESA-2008:0617 Moderate CentOS 4 ia64 vim - security update (11/26/2008 09:30 am)
- CESA-2008:0972 Important CentOS 4 i386 kernel security update (11/20/2008 04:41 pm)
- CESA-2008:0972 Important CentOS 4 x86_64 kernel security update (11/20/2008 04:40 pm)
- CESA-2008:0977 Critical CentOS 4 x86_64 seamonkey security update (11/19/2008 10:53 am)
- CESA-2008:0977 Critical CentOS 4 i386 seamonkey security update (11/19/2008 10:52 am)
- CESA-2008:0967 Moderate CentOS 4 x86_64 httpd security update (11/18/2008 11:48 am)

Related Threads RSS


Post New Comment


All products mentioned are registered trademarks or trademarks of their respective owners.
© 2002-2009 Esselbach Internet Solutions - All Rights Reserved. Terms and privacy policy
Website powered by Esselbach Storyteller CMS System