Break-in seems to have initially occurred no later than August 12th
Files belonging to ssh (openssh, openssh-server and openssh-clients)
were modified and running live. These have been uninstalled and
removed, all processes were killed and known good copies were
reinstalled. That said all users may wish to consider taking this
opportunity to change their passwords and update ssh keys (particularly
if you had an ssh private key on hera). This seems to have occurred on
or around August 19th.
ils n'ont pas de monitoring un peu sécurisant sur les changements de serveur ssh sur kernel.org ?
parce que modification du serveur ssh c'est assez grossier comme hack ...
[^] # Re: Embarrassing...
Posté par Christophe Turbout . En réponse à la dépêche Les serveurs de kernel.org ont été compromis. Évalué à 3.
ils n'ont pas de monitoring un peu sécurisant sur les changements de serveur ssh sur kernel.org ?
parce que modification du serveur ssh c'est assez grossier comme hack ...
suis-je le seul à trouver ça bizarre ?