
Open source more open than you may have imagined...
By Robert Lemos
Published: 2 December 2003 10:05 GMT
The Debian Project has warned that a flaw in the Linux kernel helped attackers compromise four of the open software project's development servers.
During several intrusions on 19 November, the flaw enabled an attacker who already had access to a server to remove the limitations that protected the system from everyday users. The technique is known as a privilege escalation.
Members of the development team found the flaw in September and fixed the latest version of the core Linux software, or kernel. The fix came a bit late, however. The latest version of the kernel, 2.4.23, was released on Friday, eight days after the Debian breach.
The Debian Project, which uses only truly open-source software in its make-up, stressed that the breaches hadn't affected the project's code base.
Martin Schulze, a developer and member of the project, said: "Fortunately, we require developers to sign the upload [software] digitally. These files are stored off-site as well, which were used as a basis for a recheck."
The development team promised to lock all developer accounts until the flaw has been found and fixed. The team published patches for the flaw on Monday as well but didn't specify when the accounts would be unlocked.
The unknown attacker compromised at least four servers. The systems - known as Master, Murphy, Gluck and Klecker - had maintained the open-source project's bug tracking system, source code database, mailing lists, website and security patches.
The attacker gained access to one of the systems by compromising a developer's computer and installing a program to sniff out the characters typed on the developer's keyboard, according to a postmortem analysis the team published Friday. When the programmer logged into the Klecker system, the attacker recorded his password.
Using the September flaw, the attacker gained owner privileges on Klecker. This is frequently referred to as "owning" the system. The flaw - in a part of the kernel that manages memory - allows only users that already have access to the system to raise their privileges. Such flaws are less critical than vulnerabilities that give an outside attacker access to a server and so are fixed less quickly.
The attacks have been the latest levelled at open source software.
In early November, an attacker attempted to corrupt the Linux kernel with a coding error that would have created a flaw similar to the one that affected the Debian Project. A year ago, malicious attackers placed spyware into a popular open-source tool, Tcpdump. Several other known attacks have also been executed against other open source projects.
Robert Lemos writes for News.com
Linux (Red Hat or Debian distributions) • Installing and maintaining Open Source Software • Operational experience with Java technologies ...
Software Engineer, Linux Kernel, Wireless, West Yorkshire, 6 months THE PROJECT: My client is looking to improve the performance of its Linux ...
Linux (Red Hat or Debian distributions) Installing and maintaining Open Source Software Operational experience with Java technologies SNMP and ...
Agenda Setters 2009
Welcome to the ninth annual Agenda Setters poll – silicon.com's list of the top 50 most influential individuals in the technology and IT industries, from techies and CIOs to entrepreneurs and business leaders. Find out more in our latest special report.
Stories from the web...
Copyright © 2008 CBS Interactive Limited. All rights reserved. Top of page
Bob Tarzey Why you must rein in your power users When they do damage, it can be catastrophic to your business
Jon Collins Is losing a mobile device really such a big deal? How to minimise the damage to your business