• # Re: Du nouveau sur les serveurs Debian compromises

    Posté par . En réponse à la dépêche Du nouveau sur les serveurs Debian compromis. Évalué à -1.

    Je pensais que c'était dans les films qu'on pouvait casser des sécurités aussi rapidement... Maintenant reste a voir combien de temps MS va mettre pour annoncer avoir trouvé un bug chez Debian :-)

    On Wednesday 19th November (2003), at approximately 5pm GMT, a sniffed
    password was used to access an (unprivileged) account on
    klecker.debian.org. Somehow they got root on klecker and installed
    suckit. The same account was then used to log into master and gain
    root (and install suckit) there too. They then tried to get to murphy
    with the same account. This failed because murphy is a restricted box
    that only a small subset of developers can log into. They then used
    their root access on master to access to an administrative account
    used for backup purposes and used that to gain access to Murphy. They
    got root on murphy and installed Suckit there too. The next day they
    used a password sniffed on master to login into gluck, got root there
    and installed suckit.

    o Klecker init timestamp: Nov 19 17:08
    o Master sk timestamp: Nov 19 17:47
    o Murphy sk timestamp: Nov 19 18:35
    o Oopses on Murphy start: Nov 19 19:25
    o Oopses on Master start: Nov 20 05:38
    o Gluck init timestamp: Nov 20 20:54

    Je trolle dès quand ça parle business, sécurité et sciences sociales