Linux Source Code Compromised

Friday, September 2, 2011 @ 12:09 PM gHale


Hackers broke into the Linux project website, Kernel.org, and made off with root access to a server known as Hera and ultimately compromised “a number of servers in the kernel.org infrastructure,” according to a note on the kernel.org website.

Administrators of the website learned of the problem Sunday and soon discovered bad things were happening on their servers. Attackers modified files, added a malicious program to the server’s startup scripts and logged some user data.

RELATED STORIES
Compromised Sites Distributing Trojan
A Trojan Distribution Network
ZeuS Spin Off Hits Cyber Street
For Sale: Trojan to Go

Kernel.org’s owners have contacted law enforcement in the U.S. and Europe and are in the process of reinstalling the site’s infrastructure and figuring out what happened.

They think the hackers may have stolen a user’s login credentials to break into the system, and the site is making each of its 448 users change their passwords and SSH (Secure Shell) keys.

This intrusion is a problem because Kernel.org is the place where Linux distributors download source code for the operating system’s kernel. But Kernel.org’s note said, even with root access, it would be difficult for a hacker to slip malicious source code into the Linux kernel. That’s because Linux’s change-tracking system takes a cryptographic hash of each published file.

So once a component of the Linux kernel publishes on Kernel.org, “it is not possible to change the old versions without it being noticed,” the Kernel.org note said.

In January, servers used by the Fedora project — the community version of Red Hat Enterprise Linux – suffered a hack attack. Around the same time another open-source software development site called SourceForge also fell victim to an intrusion.



Leave a Reply

You must be logged in to post a comment.