Free Republic
Browse · Search
General/Chat
Topics · Post Article

Skip to comments.

Linux Mint Website Hack: A Timeline of Events
SOFTPEDIA ^ | Feb 21, 2016 12:05 GMT | Catalin Cimpanu

Posted on 02/22/2016 7:26:56 PM PST by Utilizer

Last night, the Linux Mint team announced that someone had hacked their servers and started pointing user downloads to malicious ISO images for the Linux Mint 17.3 Cinnamon edition. Our Linux editor already covered the initial details of the attack, which we recommend reading before going forward with this article.

Since then, in the last ten hours, the Linux and infosec communities have been working hard to investigate what happened and how the hackers operated. Linux Mint Team: They hacked us via our WordPress site

The first to provide an answer was Clement Lefebvre, leader of the Linux Mint project, who acknowledged in a comment on the official announcement that the initial point of entry was their WordPress blog.

The hackers managed to escalate their access to the underlying server and finally get shell access to www-data, Lefebvre explained. From here they modified the Linux Mint download page to point to a malicious FTP server hosted in Bulgaria (IP: 5.104.175.212).

(Excerpt) Read more at news.softpedia.com ...


TOPICS: Computers/Internet
KEYWORDS: bulgaria; clementlefebvre; linux; linuxmint; malware; mint; wordpress
Navigation: use the links below to view more comments.
first 1-2021-23 next last
Oops! Main Linux OS repos compromised!! Mint users beware!
1 posted on 02/22/2016 7:26:57 PM PST by Utilizer
[ Post Reply | Private Reply | View Replies]

To: ShadowAce

Ping!


2 posted on 02/22/2016 7:27:25 PM PST by Utilizer (Bacon A'kbar! - In world today are only peaceful people, and the muzrims trying to kill them)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Utilizer

Script kiddie job


3 posted on 02/22/2016 7:31:08 PM PST by butlerweave
[ Post Reply | Private Reply | To 1 | View Replies]

To: Utilizer

WordPress has a million vulnerabilities.

You want to do a blog, rent a separate, dedicated server in somebody else’s data center.


4 posted on 02/22/2016 7:34:37 PM PST by proxy_user
[ Post Reply | Private Reply | To 1 | View Replies]

To: Utilizer

I was trying to get in to download a new ISO last night and couldn’t. Now I know why.


5 posted on 02/22/2016 7:41:08 PM PST by E. Pluribus Unum ("The goal of socialism is communism... Hatred is the basis of communism" --Vladimir Lenin)
[ Post Reply | Private Reply | To 1 | View Replies]

To: butlerweave

Still a problem, scriptkiddie or no. A compromised source is a danger nonetheless, notwithstanding the method that originated it.


6 posted on 02/22/2016 7:46:56 PM PST by Utilizer (Bacon A'kbar! - In world today are only peaceful people, and the muzrims trying to kill them)
[ Post Reply | Private Reply | To 3 | View Replies]

To: E. Pluribus Unum

They should have it repaired shortly. Linux coders are the best. :)


7 posted on 02/22/2016 7:47:41 PM PST by Utilizer (Bacon A'kbar! - In world today are only peaceful people, and the muzrims trying to kill them)
[ Post Reply | Private Reply | To 5 | View Replies]

To: Utilizer

Still down.


8 posted on 02/22/2016 7:54:17 PM PST by E. Pluribus Unum ("The goal of socialism is communism... Hatred is the basis of communism" --Vladimir Lenin)
[ Post Reply | Private Reply | To 7 | View Replies]

To: Utilizer
Was Linux Mint one of the distros which had been subject to etnryism by SJWs recently?
9 posted on 02/22/2016 7:55:04 PM PST by grey_whiskers (The opinions are solely those of the author and are subject to change without notice.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Utilizer

The article says, “they modified the Linux Mint download page to point to a malicious FTP server” not that they hacked the repository.


10 posted on 02/22/2016 8:00:58 PM PST by Dalberg-Acton
[ Post Reply | Private Reply | To 1 | View Replies]

To: Dalberg-Acton

Ehrmmm... you consider the misdirecting of a pointer to a site hosting a malicious main iso download page somehow not a repository?

Perhaps if someone posted a link to a Mint iso repo and then showed you the different malicious iso location you might perchance reconsider your position?

Just a thought.

My opinion, its a ‘malicious version’ repo, albeit not a compromised main/standard repo. It’s still a compromised download source.


11 posted on 02/22/2016 8:13:13 PM PST by Utilizer (Bacon A'kbar! - In world today are only peaceful people, and the muzrims trying to kill them)
[ Post Reply | Private Reply | To 10 | View Replies]

To: E. Pluribus Unum

Give it a bit of time, mate.


12 posted on 02/22/2016 8:13:41 PM PST by Utilizer (Bacon A'kbar! - In world today are only peaceful people, and the muzrims trying to kill them)
[ Post Reply | Private Reply | To 8 | View Replies]

To: grey_whiskers

I dunno. You’d have to elaborate.


13 posted on 02/22/2016 8:14:08 PM PST by Utilizer (Bacon A'kbar! - In world today are only peaceful people, and the muzrims trying to kill them)
[ Post Reply | Private Reply | To 9 | View Replies]

To: Utilizer

I have three machines running Mint. I love it, it will really bring new life to an older machine. The only one currently running is on my sons laptop, I need to check it out in the morning. Mine are dedicated machines for ham radio and have not been on in a few weeks.


14 posted on 02/22/2016 10:01:55 PM PST by DYngbld (I have read the back of the Book and we WIN!!!! (this post approved by the NSA))
[ Post Reply | Private Reply | To 1 | View Replies]

To: Utilizer
The Mint forum was also compromised. I'd stay away from the Mint website for a while.

More info here, including comments from the supposed hacker:

http://www.zdnet.com/article/hacker-hundreds-were-tricked-into-installing-linux-mint-backdoor/

15 posted on 02/22/2016 10:56:42 PM PST by TChad
[ Post Reply | Private Reply | To 1 | View Replies]

To: TChad

Thanks so much for the extra info. More information is always welcome. :)


16 posted on 02/22/2016 11:13:07 PM PST by Utilizer (Bacon A'kbar! - In world today are only peaceful people, and the muzrims trying to kill them)
[ Post Reply | Private Reply | To 15 | View Replies]

To: DYngbld

Not to denigrate Mint, but if you are looking at working with older machines there are certain distros out there specifically designed to work with older machines, even those with quite limited resources.

In rough order of less resource demands, here are a few:

1. AntiX and/or MX-14
2. Mepis 8.0 (yes, it’s older. It works.)
3. uberstudent 2.0 lxde
4. ultimate edition lite
5. Aptosid Thanatos xfce i386
6. Linux From Scratch (LFS)
7. Damn Small Linux (DSL)

Among others...

Running gparted/GPT from a bootable Rescue CD (System Rescue CD is highly recommended) to partition the drive(s) prior to installation is most strongly advised. PartImage also is helpful to recover from any difficulties in the future.

Oh, and there are also some kiosk Linux versions you might be interested in as well.

Have fun!


17 posted on 02/22/2016 11:41:03 PM PST by Utilizer (Bacon A'kbar! - In world today are only peaceful people, and the muzrims trying to kill them)
[ Post Reply | Private Reply | To 14 | View Replies]

To: DYngbld
I need to check it out in the morning.

The bad operating system ISO files were available for download only on Feb. 20. If your son's computer had Mint 17.3 installed before then, it should be OK.

18 posted on 02/23/2016 12:08:05 AM PST by TChad
[ Post Reply | Private Reply | To 14 | View Replies]

To: Bloody Sam Roberts

?ping?


19 posted on 02/23/2016 3:07:25 AM PST by Mrs. B.S. Roberts
[ Post Reply | Private Reply | To 1 | View Replies]

To: rdb3; Calvinist_Dark_Lord; JosephW; Only1choice____Freedom; amigatec; Ernest_at_the_Beach; ...

20 posted on 02/23/2016 3:28:24 AM PST by ShadowAce (Linux - The Ultimate Windows Service Pack)
[ Post Reply | Private Reply | To 1 | View Replies]


Navigation: use the links below to view more comments.
first 1-2021-23 next last

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
General/Chat
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson