Alerts This Week
Warning Icon 1 923
Alerts This Week
Warning Icon 1 923

Gentoo: GLSA-200312-01 Normal: Remote Exploit on Rsync Server

gentoo
Calendar Grey December 3, 2003
Dist Gentoo Esm H88
Gentoo has identified a critical security breach in the rsync.gentoo.org server. Users must verify their system integrity and follow recommended actions
On December 2nd at approximately 03:45 UTC, one of the servers that makes up the rsync.gentoo.org rotation was compromised via a remote exploit

Summary

- ---------------------------------------------------------------------------
GENTOO LINUX SECURITY ANNOUNCEMENT 200312-01
- ---------------------------------------------------------------------------
GLSA: 200312-01
summary: rsync.gentoo.org rotation server compromised
severity: normal
date: 2003-12-02
CVE: None
exploit: remote

DESCRIPTION:
On December 2nd at approximately 03:45 UTC, one of the servers that makes up the rsync.gentoo.org rotation was compromised via a remote exploit. At this point, we are still performing forensic analysis. However, the compromised system had both an IDS and a file integrity checker installed and we have a very detailed forensic trail of what happened once the box was breached, so weare reasonably confident that the portage tree stored on that box wasunaffected.
The attacker appears to have installed a rootkit and modified/deleted some files to cover their tracks, but left the server otherwise untouched. The box ...

Read the Full Advisory

Resolution

References

Availability

style>.gentoo_availability{display:block;}

Concerns

Synopsis

Background

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Affected Packages

Impact

Workaround

Your message here