OpenWRT has disclosed a data breach that occurred after a malicious hacker gained access to a forum admin account. The OpenWRT wiki, which contains the official download links, was not compromised, the project said.. The maintainers of OpenWRT , an open-source project that provides free and customizable firmware for home routers, have disclosed a security breach that took place over the weekend. According to a message posted on the project's forum and distributed via multiple Linux and FOSS-themed mailing lists , the security breach took place on Saturday, January 16, around 16:00 GMT, after a hacker accessed the account of a forum administrator. . OpenWRT reported a security incident where an intruder gained unauthorized entry to an administrator account on its forum, impacting the community's safety.. OpenWRT Data Breach, Firmware Security, Admin Account Compromise. . LinuxSecurity.com Team
Samba admins: get patching and/or updating. Unless you’re content to have your admin passwords overwritten by, well, anyone else using Samba.. That’s the gist of an advisory warning that “On a Samba 4 Active Directory domain controller (AD DC) any authenticated user can change other users' passwords over LDAP, including the passwords of administrative users and service accounts.” . Samba 4 Active Directory Domain Controller enables any verified user to modify administrative passwords, revealing critical vulnerabilities in security measures.. Samba Administration, Password Change Threat, Active Directory Risks, Samba Update Advisory. . LinuxSecurity.com Team
The web sites of more than a whopping 200 Australian organisations were hijacked and vandalised in a spate of hacks last week. In the largest single attack, a hacker gained administrative access to the Direct Admin server management system used by a hosting provider, who Computerworld Australia will not name, and suspended 159 accounts rendering their web sites inaccessible to the public. . The suspension notification page was then defaced with the hackers' moniker and religious propaganda. The hack was launched through a flaw created after an automatic patch of the admin system failed to complete. The link for this article located at Network World is no longer available. . The suspension notification page was then defaced with the hackers' moniker and religious propaganda. sites, whopping, australian, organisations, hijacked, vandalised. . LinuxSecurity.com Team
WordPress, the popular blogging software platform, has been updated to fix a flaw that could have enabled a hacker to change an administrator password. The bug enables a specially crafted URL to evade a password reset security verification check, Matt Mullenweg, founding developer of WordPress, said Wednesday on the organization's blog.. The link for this article located at SC Magazine is no longer available. . A significant update has been rolled out by WordPress, addressing a critical vulnerability that might enable cybercriminals to alter administrator passwords.. WordPress Update, Admin Security, Password Flaw Fix. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.