Comments on: Red Hat, Fedora servers compromised
Linux seller says Red Hat and Fedora servers were breached but customers are not affected.
Linux seller says Red Hat and Fedora servers were breached but customers are not affected.
Web sites launch all the time, but they also shut their doors. We highlight 15 that bit the dust this year.
Let the debate begin: Was the iPhone more important than iTunes? Was anything bigger than Google finding a great business model? CNET offers its list of the 10 most important stories of the '00s.
Online security is threatened by more than hacking and phishing attempts. Check here for the latest updates on software vulnerabilities, data leaks, and rapidly spreading viruses--and learn how to protect your systems.
Add this feed to your online news reader
Compared to the swiss-cheese that's Windows, yes, it is secure. Or do I need to remind you of this:
http://news.zdnet.com/2100-9595_22-111513.html?legacy=zdnn
http://www.accessmylibrary.com/coms2/summary_0286-6438492_ITM
So, let's contrast:
* Windows 2000 (and Office 2000) source code files were stolen outright, and that was after the intruders had literally months on end to play around in MSFT's networks. Meanwhile, Microsoft vehemently denied any such thing had happened until Windows 2000's source code was splattered all over the Internet, and the denials were no longer plausible. It took Microsoft months to figure out what happened, and close the holes.
One public-facing server at RedHat managed to get compromised for a short period of time, and was caught before doing anything more than token damage to one file (which you can see the source code to anyway). RH's response was open and full, a detection script and numerous other proactive methods were immediately issued, and new package keys are being generated as a precaution.
So tell me - whom would you rather trust as a vendor of a secure product?
You're doing an awful lot of apology and spinwork, Penguinisto. It would have been a better answer to simply say that no system is perfect, the servers were compromised and Red Hat took appropriate actions to address the situation. Instead you go on a FUD campaign which only derails any attempt at a legitimate and professional response. Your comments end up sounding entirely like a troll.
If it walks like a troll, talks alike a troll, and posts like a troll, then Penguinisto earns the title honestly.
@Dan: Everything I posted up there is true. Prove me wrong, that's all you need to do. Until then, you haven't a leg to stand on.
Windows *is* fairly secure, and so is Redhat. You can never be 100% secured, and that is the reality. We will continue to find such attacks on most OSs.
/P
You still have yet to prove me wrong (as does "walletless". Try if you wish, but the point still stands: MSFT is more consistently vulnerable, doesn't disclose anything that they don't absolutely have to, and puts millions of users at risk with their behaviors. RedHat OTOH does not.
Good points all. Your posting was perhaps the most sensible of them all, Walletless.
Among the security industry rumors that Fedora was hacked has been circulating for awhile now, with both Fedora and RedHat deciding to keep silent.
Then last week we hear from Fedora that some "infrastructure issues" were discovered with no explanation, only to expect intermittent failure of their servers. Nothing from RedHat.
THEN we suddenly hear rumors that there are actually TWO different intrusions: one at Fedora, and *a separate attack* on RedHat.
Only today after the rumor-mill was exploding that Fedora and RedHat made an announcement. However we are all still in the dark as to WHAT ACTUALLY HAPPENED.
What we know:
1. Several Fedora servers got hacked, including one used to sign Fedora packages. According to Fedora, their signing key was not compromised.
2. RedHat was also separately (and more seriously) hacked. The hacker was able to compromise RedHat's signing keys (!!!), then tamper & sign a number of security-related packages (!!!) including RedHat's OpenSSH distribution.
This is huge!!! It's an attack to the heart of RHN and bigger than any of those hacks at Microsoft you mentioned, because it means some RedHat's customers may have also been compromised because of this!!! Now everyone has to go back and check their packages against the blacklist.
It would be akin to a hacker getting into Microsoft's or Apple's Automatic Updates and being able to send out a tampered package. Doesn't get bigger than that!
But we still don't know HOW the compromise happened! Both Fedora and RedHat are keeping their customers in the dark. Is there an undisclosed gaping remotely-exploitable security hole in Fedora & RedHat?? If I were running either I won't be sleeping well tonight. RedHat should come clean instead of still keeping silent.
Mr. Benedict,
You are just wrong. Red Hat's signing keys were not compromised. You can read details about the keys at
http://www.awe.com/mark/blog/200701300906.html
RHN was NOT compromised, no unauthorized packages were uploaded into the RHN systems.
Both the Fedora team and Red Hat have given details about the incident.
As far as not doing your homework or just being a full of it, it doesn't get bigger than you.
The attacker *WAS ABLE TO SIGN REDHAT PACKAGES*. Which de facto means the signing keys are compromised, however you choose to bury your head in the sand or not. The link you posted from early 2007 doesn't add any value whatsoever to this discussion.
Think of a computer as a house. A truly secure system would have motion detectors in each room. So, just because you were able to break through the front door or side window, you wouldn't be allowed to go anywhere else in the house. Instead, Unix security is like a house with a big lock on the front door but with nothing else. That lock often keeps people out, but once you get in, you have access to every room in the entire house.
That is not a secure system.
Nothing is secure. Unix/Linux is better than most (all?) OS's out there at it, but it's not perfect either. Using your house analogy, there are some popular OS's out there which will remain unnamed that have nothing but a few strips of police tape across the unlocked door. At least Unix locks the door.
1. The modern "Unix" kernel implement sophisticated compartments. A compromise in one part of the OS does not mean the entire OS is compromised. A password changing program in your example can be restricted to modify objects labeled as passwords, nothing else. We call this Trusted Computing Base (TCB). For Linux in particular, TCB has been available since 2000 (thanks to the NSA and their work with SE-Linux), and has been part of the mainline kernel since 2003 when SE-Linux patches were merged into kernel 2.6. It is standard on RedHat since 4.0, and the NSA patches also made it into FreeBSD and Darwin. Other Unices such as Solaris and AIX have had TCB options forever now.
2. Outside the kernel, in practice Unix administrators do not use an "all powerful root" anymore. Instead administration is done typically using a program called "sudo". Sudo limits what admins can do. Also some Unices (such as FreeBSD) have "secure levels" where even the "all powerful root" is actually restricted from doing many operations when running in multi-user mode. I.e., your compromised password-changing program still cannot overwrite critical system files, for example.
3. Also, a common Unix administration practice over the past few years is the use of virtualization (e.g., Solaris Zones, HP-UX VPARs, FreeBSD jail, etc.) Services are relegated to different zones, so a compromise in one zone does not affect other zones. This is becoming even more popular today with the advent of hypervisors.
4. In security conscious environments (e.g., certain financial institution systems or government systems) typically there is an access management system that's run on top of Unix. A popular example is the "eTrust Access Control" system made by Computer Associates. Like TCB, eTrust places strict controls on what users and processes (including those running as "root") can and cannot do. eTrust also provides alerting and audit logging.
# The signed tampered packages were:
#
# openssh-3.9p1-8.RHEL4.24 for i386, x86_64 architecture
# openssh-3.9p1-9.el4 for i386, x86_64 architecture
# openssh-4.3p2-26 for x86_64 architecture
# openssh-4.3p2-26.el5 for x86_64 architecture
fortunately, my server's version is still openssh-4.3p2-24.el5....
- by gmbidols August 26, 2008 6:04 AM PDT
- Very Nice Blog. I Like Your Blog Please Visit My Website and Give Your Review.
- Like this Reply to this comment
-
(27 Comments)http://www.gmb.in/ http://www.ancientpeaks.com