Donate!
Welcome, Guest. Please Login or Register :: View Members
Pages: 1
Send Topic Print
Linux Mint site got hacked last weekend (Read 107 times)
Oldfeller--FSO
Serious Thumper
ModSquad
*****
Online

Hobby is now
"concentrated
neuropany"

Posts: 12673
Fayetteville, NC
Gender: male
Linux Mint site got hacked last weekend
02/24/16 at 21:00:26
 

Bulgarians attack French based Linux Mint Cinnamon 17.3

A Bulgarian hacker group claimed Monday that they had hacked the Linux Mint Website and had "taken over the ISO's and the repositories", substituting in modified ISO and program items that turned your Linux Mint Cinnamon 17.3 installation into their personally owned worker bot farm.

It turned out that it was really the fourth or fifth such visit from the Bulgarian marauder group and Clem Lefever's distro now has a totally destroyed security rep at this point in time.


========================================


Can Clem get it back?    Being a one man show you are talking about a man-year to do the laborious task, and Clem has now shut down all the mirrors and main repositories to begin the work at this time.

Why did the Bulgarians do it?   They say they needed the $89 they are getting each time from  selling the members/password listing and the $100+ a month they are getting from selling the bot-farm processing power.

Suspecious minds suspect an organized paid attack was made on Clem's webpages with some sort of commercial payback intended for somebody within the next few years.


Clem was attacked using a Wordpress exploit that still exists and since the hackers got in to Clem's passwords it is obvious they have had a lengthy chance to put back doors in all over the place in the two months that the mice ran around inside the walls.



=========================================



I look for a lot of discussion about better Linux website security and a total complete  blacklisting of programs like Wordpress that have any known issues that are ongoing and ARE NOT BEING INSTANTLY FIXED by their owners.

I have also checked my own machine and I am not currently affected at this time -- but I trust that to stay true about like wormy dogshite stinking on hot pavement.

VERY DUBIOUS and smelly .......


Am now looking for a new linux distro now, too.



One man maintained distros are very vulnerable to any organized sort of evil hacking activity.

One person can only focus on one thing at a time.    

And they have to sleep sometimes too.

Back to top
 
 

Former Savage Owner
  IP Logged
Oldfeller--FSO
Serious Thumper
ModSquad
*****
Online

Hobby is now
"concentrated
neuropany"

Posts: 12673
Fayetteville, NC
Gender: male
Re: Linux Mint site got hacked last weekend
Reply #1 - 02/24/16 at 21:16:41
 

Who benefits the most from this successful Paid For attack on the ex-#1 (now #5 and dropping like a rock) Linux distro?

Well then, if that is too hard for you ----- who routinely uses FUD tactics to achieve their business goals?
Back to top
 
« Last Edit: 02/25/16 at 04:57:54 by Oldfeller--FSO »  

Former Savage Owner
  IP Logged
old_rider
Serious Thumper
*****
Offline

Backyard Bill
Productions

Posts: 3147
flordia panhandle
Gender: male
Re: Linux Mint site got hacked last weekend
Reply #2 - 02/24/16 at 22:22:43
 
One man? I thought this was a "shared" "open source" OS?

Your saying one man writes all this stuff? And here I thought it was a group of programmers together with an unshakeable software program.

I need to read up on stuff more... maybe i'll write the local group and ask them what they are doing, they keep sending me emails with attachments on their meeting notes and upcoming stuff..... which I refuse to open.

Back to top
 
 

We are here to laugh at the odds and live our lives so well that Death will tremble to take us.
  IP Logged
Oldfeller--FSO
Serious Thumper
ModSquad
*****
Online

Hobby is now
"concentrated
neuropany"

Posts: 12673
Fayetteville, NC
Gender: male
Re: Linux Mint site got hacked last weekend
Reply #3 - 02/25/16 at 04:24:50
 

A "one man" distro is one man doing most of the work and gleaning what he needs from LENARO and other FOSS supermarkets.

Linux Mint is a simple rewrite of Ubuntu.   So Clem was picking bits and pieces from Ubuntu and lots of other open sources and writing just the new code to blend it together.

Clem did not pay enough attention to website security, and he is paying the price for that error now.

The "other folks" that keep getting mentioned run the other forks of Mint, which use Clem's modified Ubuntu and add other forms of front end to it to make the different versions.

This current mess could Kill the Whole thing, or it could cause it to grow up stronger.   "Trust" has been badly violated by the repeated Bulgarian attacks.

That is up to Clem's personality type I do believe.

I suspect the web site to get locked down MUCH more strongly, ASAP.
Back to top
 
 

Former Savage Owner
  IP Logged
Oldfeller--FSO
Serious Thumper
ModSquad
*****
Online

Hobby is now
"concentrated
neuropany"

Posts: 12673
Fayetteville, NC
Gender: male
Re: Linux Mint site got hacked last weekend
Reply #4 - 02/25/16 at 05:01:27
 

Clem speaks .....  upfront and honest.   Not avoiding the issues, not dodging the problems ......

example:  Edit by Clem: Thanks for reporting this, this is a second attack so it means we’re still vulnerable. I’m shutting the server down right now.


http://blog.linuxmint.com/?p=2994



The people in charge of Wordpress are getting a large serving of grief for NOT TAKING CARE OF THEIR KNOWN VULNERABILITY ISSUES .......
Back to top
 
 

Former Savage Owner
  IP Logged
Oldfeller--FSO
Serious Thumper
ModSquad
*****
Online

Hobby is now
"concentrated
neuropany"

Posts: 12673
Fayetteville, NC
Gender: male
Re: Linux Mint site got hacked last weekend
Reply #5 - 02/25/16 at 05:08:56
 

Somebody is paying renegade hacker groups to attack selected Linux Distros ...... once the proof of this comes out  you can expect the EU to take some drastic actions against such parties ...............
Back to top
 
 

Former Savage Owner
  IP Logged
Oldfeller--FSO
Serious Thumper
ModSquad
*****
Online

Hobby is now
"concentrated
neuropany"

Posts: 12673
Fayetteville, NC
Gender: male
Re: Linux Mint site got hacked last weekend
Reply #6 - 02/25/16 at 05:15:04
 

"Open-ness" is being adversely affected by the levels of lock-down required by the POST Attack period ......   it is a needed thing, however.
Back to top
 
 

Former Savage Owner
  IP Logged
old_rider
Serious Thumper
*****
Offline

Backyard Bill
Productions

Posts: 3147
flordia panhandle
Gender: male
Re: Linux Mint site got hacked last weekend
Reply #7 - 03/01/16 at 06:11:59
 
Will previous versions of mint be affected? I am still debating wether or not to load it back up on the little laptop.
I had 16 running last, until it errored on me and would not boot.
I wanted to test some steam stuff using mint 16, on a couple new games I purchased.
I figure as long as I didn't hit the site, or download any type of updates I would be ok.... but with all this going on now, I might just wait.
Back to top
 
 

We are here to laugh at the odds and live our lives so well that Death will tremble to take us.
  IP Logged
Oldfeller--FSO
Serious Thumper
ModSquad
*****
Online

Hobby is now
"concentrated
neuropany"

Posts: 12673
Fayetteville, NC
Gender: male
Re: Linux Mint site got hacked last weekend
Reply #8 - 03/01/16 at 12:23:36
 

Feb 17-21 were the only infected dates

The only ISO image replaced with a back door fake was Linux Mint 17.3 ,  Cinnamon

All older and newer images are good at this time.

All mirrors have been pulled down, so you can only get Linux Mint from the home repository at this time (which is being watched closely, BTW).



==========================================



Clem is working to get his web pages off of Wordpress (he was using a old version, btw)

The Linux Mint distro is due to roll up to the next Ubuntu base soon,   and one would suspect Clem will elect to include more of the security features included in Ubuntu as part of Mint this time around.

Clem got sucker punched in the nuts by the Bulgarians, but I do not doubt he has learned a good bit from the experience --- this will show up in the next Mint levels I do suspect.

Question still remains -- who paid the Bulgarians ?
Back to top
 
 

Former Savage Owner
  IP Logged
Art Webb
Serious Thumper
*****
Offline

SuzukiSavage.com
Rocks!

Posts: 3007
columbus, Texas
Gender: male
Re: Linux Mint site got hacked last weekend
Reply #9 - 03/01/16 at 13:45:07
 
easy answer: follow the money
who stands to benefit if linux goes away?
Back to top
 
 
  IP Logged
Oldfeller--FSO
Serious Thumper
ModSquad
*****
Online

Hobby is now
"concentrated
neuropany"

Posts: 12673
Fayetteville, NC
Gender: male
Re: Linux Mint site got hacked last weekend
Reply #10 - 03/02/16 at 01:37:41
 

Easy answer, but no proof yet would be our old FUD buddy MS ......

If you are afraid (caught up in manufactured Fear and Uncertainty)  to dual boot Linux Mint (or Ubuntu) your chances of locking yourself into Win 10 go up greatly.

Guess who just broke all my AMD Catalyst drivers for my video card for me yet again .......

This sucks, but MS told everybody last month that they were going to delete all "conflicting" drivers and software programs and sure enough they are ruining your machine now late at night (whether you have Win 10 loaded or not makes no difference to the Borg, that software or driver is on the kill list).



Tongue

Back to top
 
 

Former Savage Owner
  IP Logged
Art Webb
Serious Thumper
*****
Offline

SuzukiSavage.com
Rocks!

Posts: 3007
columbus, Texas
Gender: male
Re: Linux Mint site got hacked last weekend
Reply #11 - 03/02/16 at 06:50:52
 
Well I think I'm safe from that at least, my OS is still as- delivered, aside from Chrome browser
they mess with that, it's trashcan city
Back to top
 
 
  IP Logged
Pages: 1
Send Topic Print


« Home

 
« Home
SuzukiSavage.com
09/28/24 at 16:24:56



General CategoryThe Cafe › Linux Mint site got hacked last weekend


SuzukiSavage.com » Powered by YaBB 2.2!
YaBB © 2000-2007. All Rights Reserved.