Latest Comments
"trend is good antivirus software."
by jack | Dec 3, 2008 7:02 AM
 
"I feel it with you guys. These irritating interruptions on privacy MUST be stopped. It is a ..."
by Jan Wilmans | Dec 2, 2008 7:11 PM
 
"My AVG WILL NOT UPDATE"
by James Downs | Dec 2, 2008 5:58 AM
 
"Concerned man's comments seem to intimate that if I'm using agents all will be well but the ..."
by Werner K | Nov 26, 2008 8:36 PM
 
"That will enhance Microsoft Office system, including SharePoint - good platform for enterprise ..."
by SGE | Nov 25, 2008 3:29 PM

Red Hat admits to getting hacked

  • Email a Friend
  • Print Page
Red Hat admits to getting hacked
By Iain Thomson
Aug 26, 2008 11:37 AM | 1 Comment
Tags: Red | Hat | admits | to | getting | hacked |
The organisation has acknowledged the attack, and on the Fedora servers as well.

It says that it is investigating to see if data was stolen or malware introduced to its systems.

“In connection with the incident, the intruder was able to get a small number of OpenSSH packages relating only to Red Hat Enterprise Linux 4 (i386 and x86_64 architectures only) and Red Hat Enterprise Linux 5 (x86_64 architecture only) signed.

“As a precautionary measure, we are releasing an updated version of these packages and have published a list of the tampered packages and how to detect them. To reiterate, our processes and efforts to date indicate that packages obtained by Red Hat Enterprise Linux subscribers via Red Hat Network are not at risk.”

It seems the hacker or hackers were more intent on getting software signed off than infiltrating Red Hat’s deployment system, which may have allowed them to insert malware into all future deployments if undetected.

The Fedora hack seems more serious, and the organisation has called on system administrators to update their system with new keys.

“While there is no definitive evidence that the Fedora key has been compromised, because Fedora packages are distributed via multiple third-party mirrors and repositories, we have decided to convert to new Fedora signing keys,” it said

“This may require affirmative steps from every Fedora system owner or administrator.”

Red Hat has not disclosed the specific vulnerability that allowed the intrusion onto its systems.

Copyright © 2008 vnunet.com

 
Ads by Google
Thoughts on this article? Add a comment below.
Comments: 1
I got notified about this from a friend and i did not believe it; so i looked it up on Google and then i was brought here. I am worried that this could happen, i think that it should have been more secured and that the servers should be looked after better. We leave our computers and their updates in Red Hat's hand and things go wrong. I am dissapointed. ~ Mike
SC Magazine - comments icon Posted by Mike SwanSep 17, 2008 8:30 PM
Report this comment as offensive:

   * Indicates information we require to process your submission.

Name: *
Email: *
Reason for offense: *
Your report will not be displayed.  
Name:
*
 
Email:
(will not be displayed)
*
 
Comment:
(HTML not permitted)
*
 
Validation
*

Enter the code you see below:

 

 
 
 
 
 
Tripwire - Click here to win an iTouch
 
 
Vulnerabilities & Exploits Whitepapers