·ChinaUnix首页 ·论坛 ·博客 
Linux首页 | Linux新闻 | Linux论坛 | Linux文档 | Linux下载 | Linux博客 | Linux搜索 | 开源项目孵化平台 | 《开源时代》
新手入门 | 安装启动 | 管理员指南 | 开发手册 | 桌面应用 | 程序开发 | 数据库 | 网络技术| CentOS | Fedora | MySQL | Apache | Ubuntu | Gentoo| OSCON08
  Linux时代 >> 新闻
 
Red Hat服务器受到攻击 客户不会受到影响
来源: Linux论坛  日期: 2008.08.23 21:51 (共有条评论) 我要评论
 
8月23日消息,Red Hat本周五警告称,该公司部分支持商业和免费版Linux的服务器受到了网络攻击。

据国外媒体报道称,Red Hat在一份安全公告中表示,该公司相信这次攻击没有危及Red Hat Network,因此客户不会受到攻击。Red Hat利用Red Hat Network发布Red Hat Enterprise Linux的升级包。

Red Hat还发布了一个能够探测受到攻击的OpenSSH软件包的脚本文件。

Red Hat在安全公告中称,“我们发布安全警告主要针对那些不通过官方渠道获得我们二进制文件包的客户。”

受这次攻击影响的主要是少量与Red Hat Enterprise Linux 4和5相关的OpenSSH软件包,Red Hat将发布这些软件包的升级版本。Red Hat已经发布了一个受影响的软件包清单,并公布了如果探测它们的说明。

Fedora项目的一名负责人在一个Fedora电子邮件列表中发布了一份安全公告称,上周发现一些服务器受到非法访问后,他们已经断开部分服务器的网络连接。

来源:赛迪网

From the "this isn't good news" files:

Servers for both Red Hat Enterprise Linux and Fedora Linux were compromised in recent weeks by some kind of illegal access. Neither project however is currently admitting than any of their software or users were in any way directly affected by the illegal access.
Fedora Project Leader Paul Frields wrote in a mailing list entry that:

    Last week we discovered that some Fedora servers were illegally accessed. The intrusion into the servers was quickly discovered, and the servers were taken offline.Security specialists and administrators have been working since then to analyze the intrusion and the extent of the compromise as well as reinstall Fedora systems.

On the Red Hat Enterprise side of things there is an OpenSSH update notification that contains (few) details about what happened.

    Last week Red Hat detected an intrusion on certain of its computer systems and took immediate action. While the investigation into the intrusion is on-going, our initial focus was to review and test the distribution channel we use with our customers, Red Hat Network (RHN) and its associated security measures. Based on these efforts, we remain highly confident that our systems and processes prevented the intrusion from compromising RHN or the content distributed via RHN and accordingly believe that customers who keep their systems updated using Red Hat Network are not at risk.

The fear in both cases is that an attacker could have somehow gained access and then created or compromised a security signing key used to distribute packages and updates.

As far as I can tell based on the analysis provided by Red Hat that's not the case and Red Hat and Fedora are being responsible and prudent by locking down system, analyzing everything and re-issuing keys.

仔细看来,应该有部分服务器已经被攻陷,部分软件可能遭到替换,建议适用最新更新红帽软件包的用户仔细查看受感染的软件包明细。排除隐患。

[ 本帖最后由 Send_linux 于 2008-8-23 21:57 编辑 ]
  发表评论 查看评论(共有条评论)
 
 


最新资讯更多>> 
· 金山卫士开源计划首周源码下载..
· 谷歌劝说诺基亚采用Android操作..
· 11月份Linux市场占有率升至5%
· Apache 基金会确认退出 JCP 执..
· Chrome 10 新功能探秘:新增GP..
· 金山宣布开源其安全软件
· 开源FTP服务器ProFTPD发现后门
· 女黑客在开源会议上抱受骚扰
· 21款值得关注的Linux游戏
· 马化腾:腾讯半年后彻底转型,..
论坛热点更多>> 
· Linux系统移植从零开始!参与..
· 学习linux的意义在哪里
· 使用netfilter在哪能获取到原..
· 哥纠结了
· 一个在线读开源代码的工具,..
· 为什么我的目录下没有.cshrc..
· 初学linux从哪里开始
· linux 系统无法上网
· 新手安装UCenter 时总是出错..
· cacti添加主机显示的状态都是..
文档更新更多>> 
· 菜鸟入门三星ARM11嵌入式系统,是..
· 寻redhat 5.3 的中文手册 for ia64
· 请问redhat 5.3 企业版的用户手册..
· LINUX与UNIX SHELL编程指南(中文)
· 一些基本用户管理以及基本安装方法
· 菜鸟学习linux笔记与练习-----第..
· 菜鸟学习linux笔记与练习-----第..
· 服务器配置:Squid配置详解
· linux下u盘使用
· ubuntu dynamips 绑定网卡到虚拟机
 
关于我们 | 联系方式 | 广告合作 | 诚聘英才 | 网站地图 | 友情链接 | 免费注册

Copyright © 2001-2009 ChinaUnix.net All Rights Reserved

感谢所有关心和支持过ChinaUnix的朋友们

京ICP证:060528号