On CBS MoneyWatch: Deal or no deal? 8 lousy 'bargains'
BNET Business Network:
BNET
TechRepublic
ZDNet

August 15th, 2007

Ubuntu servers hacked to attack others

Posted by Ryan Naraine @ 10:49 am

Categories: Botnets, Browsers, Data theft, Exploit code, Hackers, Metasploit, Open source, Passwords, Patch Watch, Privacy, Responsible disclosure, Rootkits, Vulnerability research

Tags: Security, Ubuntu, Attacker, Server, Ryan Naraine

Finger pointing as Ubuntu servers hacked

More than half of Ubuntu’s production servers had to be pulled offline after a security breach caused those servers to actively attack other machines.

According to a notice in the Ubuntu weekly newsletter, 5 of the 8 servers that are loco hosted had to be shut down after an investigation showed a variety of security problems.

The servers were found to be missing security patches, using insecure protocols (FTP without SSL) to access the machines and without upgrades past breezy due to problems with the network cards and later kernels.

“The situation has become untenable,” Ubuntu’s Jono Bacon said in an e-mail outlining changes to the loco server policy.

Some details on the breach:

  1. The servers, especially zambezi were running an incredible amount of web software (over 15 packages recognized) and of all the ones where it’s trivial to determine a version, they were without exception out-of-date and missing security patches. An attacker could have gotten a shell through almost any of these sites.
  2. FTP (not sftp, without SSL) was being used to access the machines, so an attacker (in the right place) could also have gotten access by sniffing the clear-text passwords.
  3. The servers have not been upgraded past breezy due to problems with the network card and later kernels. This probably allowed the attacker to gain root.

A post on Slashdot notes that there is a blame game going on between Canonical (the company that sponsors the servers) and the community administrators who are being blamed for poor security practices.

Ryan NaraineRyan Naraine is a journalist and security evangelist at Kaspersky Lab. He manages Threatpost.com, a security news portal. Here is Ryan's full profile and disclosure of his industry affiliations.


Email Ryan Naraine

For daily updates on Ryan's activities, follow him on Twitter.

Subscribe to Zero Day via Email alerts or RSS.

  • Talkback
  • Most Recent of 193 Talkback(s)
THIS is why you install SELinux.
I am a proud linux user, and one thing I will tell you is, Ubuntu has little security compared to other distros. Fedora uses SELinux, which may not be THAT great, but it still helps. All my systems ru... (Read the rest)
Posted by: bendib Posted on: 11/06/09 You are currently: a Guest | | Terms of Use
"... community administrators ..."?  Anton Philidor | 08/15/07
No disagreement there (nt)  Michael Kelly | 08/15/07
How?  kmashraf | 08/16/07
Who wants to buy a cow?  Ole Man | 08/19/07
Layer 8 problem  MisterGilles | 08/15/07
Yeah.  odubtaig | 08/15/07
Note it said breezy  bobsherrill@... | 08/15/07
He's not wrong though.  odubtaig | 08/15/07
Why not? It's the same "logic" used against Windows.  ye | 08/15/07
Message has been deleted.  mdsmedia | 08/16/07
Message has been deleted.  GeoNorth | 08/16/07
What makes todays Linux more secure than Breezy?  ye | 08/16/07
What makes today's Windows more secure than 98?  Sabz5150 | 08/16/07
Windows 98 was not designed with security.  ye | 08/16/07
Do you really  Sabz5150 | 08/16/07
Quit Fighting  lmenningen | 08/16/07
Although . . .  JLHenry | 08/16/07
Where have you been?  xuniL_z | 08/16/07
Some of us . . .  JLHenry | 08/16/07
Why should he be defending Ubuntu?  ye | 08/16/07
JLHenry  xuniL_z | 08/16/07
You can't  Jambalaya Breath | 08/16/07
Breezy?  aussieblnd@... | 08/16/07
Layer 8 problem  aussieblnd@... | 08/16/07
That's right  Jambalaya Breath | 08/16/07
That's just incompetence.  odubtaig | 08/15/07
Did I read the article that goes with that headline??  mdsmedia | 08/15/07
correction....RTFA (first paragraph!!)  mdsmedia | 08/15/07
Wha????  ejhonda | 08/15/07
Well  Suicida| | 08/15/07
Wonderful Linux Security  Tiggster | 08/15/07
Oh typical.  odubtaig | 08/15/07
He is following your example...  No_Ax_to_Grind | 08/15/07
Indeed?  odubtaig | 08/15/07
Not Quite Accurate  spam_here | 08/16/07
Technically, No_clue_to_buy may be right.  nighthawk808 | 08/19/07
Iwas wondering when the Big Kahuna . . .  JLHenry | 08/16/07
How dare you  nighthawk808 | 08/19/07
One incident? Or breezy was a open invite to root? Which way you going here  xuniL_z | 08/15/07
You missed ONE small but very  Linux User 147560 | 08/15/07
bah, dang you LU  Monkey_MCSE | 08/15/07
Well feel fortunate....  xuniL_z | 08/16/07
Man, you must really  Linux User 147560 | 08/16/07
Well.  xuniL_z | 08/16/07
re:xuniL_z...don't waste your time on "Linux user"...  fr0thy2. | 08/16/07
Moreso than you do...  Linux User 147560 | 08/16/07
I'll let you have the next one!  Linux User 147560 | 08/16/07
re: I'll Let you have the next one  xuniL_z | 08/16/07
Did you think of that all by yourself?!  Linux User 147560 | 08/16/07
see what I mean...  fr0thy2. | 08/16/07
Well aren't you just the fine and dandy!  Linux User 147560 | 08/16/07
yoiu are seeing just ONE example....from yesterday alone!  xuniL_z | 08/16/07
By whose count again?  odubtaig | 08/16/07
Someday.....just maybe....you will see why  xuniL_z | 08/16/07
No, see most of the Linux kernel exploits  Linux User 147560 | 08/16/07
Let's be clear.......and you clearly LOSE.  xuniL_z | 08/16/07
Obviously you do lean that  Linux User 147560 | 08/16/07
Did you come up with that!?!  xuniL_z | 08/16/07
Do you know what reality is?  Linux User 147560 | 08/16/07
And the world is just pouring in...  fr0thy2. | 08/16/07
LU.  xuniL_z | 08/18/07
yoiu?  aussieblnd@... | 08/16/07
Focus on spelling errors ruins your credibility.  ye | 08/16/07
Did you hear the one  xuniL_z | 08/16/07
Say what?  mgcarley-zdnet | 08/18/07
Ohhhh there you are....  fr0thy2. | 08/16/07
Seems I have a secret admirer!  Linux User 147560 | 08/16/07
either you are blind or just plain  Monkey_MCSE | 08/15/07
Speaking of "Stupid"  xuniL_z | 08/16/07
man you should get out of IT...  Monkey_MCSE | 08/16/07
I was wondering about the Ubuntu  jackie40d@... | 08/16/07
You have no clue  xuniL_z | 08/16/07
xunil, you are pathetic..  Monkey_MCSE | 08/16/07
Whatever.....  xuniL_z | 08/16/07
xuniL_z, here's an old saying that you should take to heart:  nighthawk808 | 08/19/07
Many MS flaws don't hit the press -- even ones from Microsoft  peery@... | 08/17/07
Apparently . . .  JLHenry | 08/16/07
I have three words for you:  odubtaig | 08/15/07
If only......  xuniL_z | 08/16/07
Uhuh?  odubtaig | 08/16/07
oh please  xuniL_z | 08/16/07
Some more words.  odubtaig | 08/15/07
I suspected you wouldn't leave it alone with only  xuniL_z | 08/16/07
Bang on.  Marty R. Milette | 09/05/07
I'm a Linux fanboy  Jambalaya Breath | 08/17/07
Hundreds of incidents?  BroGnorik | 08/15/07
Well since the  Linux User 147560 | 08/16/07
Pure fiction  lutherlarry | 08/17/07
Maybe you better go look at what the differences  Linux User 147560 | 08/17/07
There's a difference between 100% the same and based on the same code.  ye | 08/17/07
Uh. no they are not  Linux User 147560 | 08/18/07
You misunderstood what I meant with the word  ye | 08/18/07
True,  notsofast | 08/16/07
No, it's not  magcomment | 08/15/07
Nope  Sabz5150 | 08/16/07
No it is not  jackie40d@... | 08/16/07
Don't ignore the obvious  Tiggster | 08/15/07
We're talking about SERVERS, right?  CobraA1 | 08/15/07
These were not official Ubuntu servers  bportlock | 08/15/07
Yes, in the real world...  erikmidtskogen | 08/16/07
Linux is not user friendly  YinToYourYang-22527499 | 08/15/07
It's friendly  magcomment | 08/15/07
It's friendly  Qbt | 08/15/07
Wrong answer, but thanks for playing  magcomment | 08/15/07
Oops, typo in that reply  magcomment | 08/15/07
The market picked Windows over DOS/OS2  alaniane@... | 08/16/07
Picked  Jambalaya Breath | 08/17/07
I disagree  voska | 08/15/07
Intuitive is a bunch of crap.  ajole | 08/15/07
Linux is user friendly till you try to  SO.CAL Guy | 08/16/07
Windows is  alaniane@... | 08/16/07
If you're not careful  Ole Man | 08/18/07
Are you  Linux User 147560 | 08/15/07
linux eassy haha?  ericsami | 08/15/07
In which part of last century did you use Linux?  mdsmedia | 08/16/07
I booted up in XP the Other . . .  JLHenry | 08/16/07
XP boot times...  dchase@... | 08/16/07
Nope.  JLHenry | 08/16/07
GRUB  pj_mouse | 08/16/07
If you want something close to Windows  jackie40d@... | 08/16/07
It is your attitude that keeps linux back  ericsami | 08/16/07
A few points.  nighthawk808 | 08/19/07
I don't know . . .  JLHenry | 08/16/07
I haven't compiled a kernel  Linux User 147560 | 08/16/07
easy for me  geno_zd | 08/16/07
No wonder Linux isn't easy for you  Ole Man | 08/18/07
Hey, I *like* compiling my own kernels.  nighthawk808 | 08/19/07
Ummm don't think so..and it's opinion Numb xxts...  fr0thy2. | 08/16/07
You are soooo correct!  Linux User 147560 | 08/16/07
In Soviet Russia,  nighthawk808 | 08/19/07
User Friendly....  Suicida| | 08/15/07
WARNING: Do not read as this response is to possible troll attempt  netuzer | 08/16/07
I am guessing  jackie40d@... | 08/16/07
user freindly? yes and no  mark@... | 08/17/07
Remember: Just because it's *nix doesn't mean you can be lax about security  CobraA1 | 08/15/07
Correct  itpro_z | 08/15/07
Breezy badger...  bportlock | 08/15/07
It's sad that anyone needs a wake up call  magcomment | 08/15/07
This illustrates...  GeoNorth | 08/16/07
I'm kinda surprised they . . .  JLHenry | 08/16/07
The mind boggles, those are the only things I do worry about.  odubtaig | 08/15/07
BINGO!  Linux User 147560 | 08/15/07
Well that shoots holes all through  xuniL_z | 08/16/07
One of the things I used to like about Linux...  jasonp@... | 08/15/07
..and roger  Suicida| | 08/15/07
HEEEELLLLO .. Linux Geek, where are you?  babyboomer57 | 08/15/07
Never thought I'd say this, but...  THEE WOLF | 08/15/07
what is this article all about?  patibulo | 08/16/07
I'm betting they drew straws to see who was gonna write this one  mdsmedia | 08/16/07
Remember why the servers were unpatched?  cquirke | 08/16/07
You can have the most secure bank vault in the world, but...  Scrat | 08/16/07
Oh no ther're not  ConfusedOne | 08/16/07
How BREEZY got it's name....  xuniL_z | 08/16/07
How Zuny got his name.....  Ole Man | 08/18/07
Ahhh...  dchase@... | 08/16/07
That would be because  Linux User 147560 | 08/16/07
And all 10 of you count for that...hahahahahah  fr0thy2. | 08/16/07
Please do...  Linux User 147560 | 08/16/07
Let's Try to Remember Something Here:  Billsey | 08/16/07
Absolutely - let's have some real news please  dventer@... | 08/16/07
(Linux != Windows) = HackFree  cwallen19803 | 08/16/07
Only a fanboy/girl says linux is hack free...  keepu | 08/18/07
Dayum, I hoped never to see this...  gmureddu@... | 08/16/07
These were NOT "production servers"  angrykeyboarder | 08/16/07
Hey where is the Troll "Linux User"...don't see any smart ass comments...  fr0thy2. | 08/16/07
Well if you posted something  Linux User 147560 | 08/16/07
Actually you embarrass most Linux Users...  fr0thy2. | 08/16/07
Forgot something...  fr0thy2. | 08/16/07
I only use Windows because I have to at work  Linux User 147560 | 08/16/07
Actually, it's quite easy...for a coder...  fr0thy2. | 08/16/07
Well that puts you right on par  Linux User 147560 | 08/16/07
LOL  Linux User 147560 | 08/16/07
My point exactly - thank you.  fr0thy2. | 08/16/07
You have a point?  Linux User 147560 | 08/16/07
What matters is not the number of holes found  erikmidtskogen | 08/16/07
Misleading title  carbonred | 08/16/07
Cue The Linux Geeks  bmore_bro69@... | 08/17/07
Why Breezy  ripcrd | 08/17/07
Breezy is irrelevant. I am willing to bet the breach was...  ye | 08/17/07
test  xuniL_z | 08/18/07
....  xuniL_z | 08/18/07
...  xuniL_z | 08/18/07
Keep trying.  nighthawk808 | 08/19/07
How will he know?  Ole Man | 08/19/07
Come to think of it,  nighthawk808 | 08/19/07
ZDBet - you should be spanked  GreenGeek | 08/19/07
If this is News... then it's a rag ;^}  thx-1138_@... | 08/19/07
Now that the shoes is on the other foot.  ye | 08/20/07
Yes .. indeed  thx-1138_@... | 08/23/07
This is great news!  nighthawk808 | 08/21/07
XP Boot Issues - to Techies & the 'Not-so-.  thx-1138_@... | 08/23/07
Apologies to our less-technical readers  thx-1138_@... | 08/29/07
THIS is why you install SELinux.  bendib | 11/06/09

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

advertisement

Recent Entries

Archives

Favorite Links

ZDNet Blogs

White Papers, Webcasts, and Downloads

SmartPlanet

Click Here