·ChinaUnix首页 ·论坛 ·博客 
Linux首页 | Linux新闻 | Linux论坛 | Linux文档 | Linux下载 | Linux博客 | Linux搜索 | 开源项目孵化平台
新手入门 | 安装启动 | 管理员指南 | 开发手册 | 桌面应用 | 程序开发 | 数据库 | 网络技术| CentOS | Fedora | MySQL | Apache | Ubuntu | Gentoo| OSCON08
  Linux时代 >> 新闻
 
Red Hat服务器受到攻击 客户不会受到影响
来源: Linux论坛  日期: 2008.08.23 21:51 (共有条评论) 我要评论
 
8月23日消息,Red Hat本周五警告称,该公司部分支持商业和免费版Linux的服务器受到了网络攻击。

据国外媒体报道称,Red Hat在一份安全公告中表示,该公司相信这次攻击没有危及Red Hat Network,因此客户不会受到攻击。Red Hat利用Red Hat Network发布Red Hat Enterprise Linux的升级包。

Red Hat还发布了一个能够探测受到攻击的OpenSSH软件包的脚本文件。

Red Hat在安全公告中称,“我们发布安全警告主要针对那些不通过官方渠道获得我们二进制文件包的客户。”

受这次攻击影响的主要是少量与Red Hat Enterprise Linux 4和5相关的OpenSSH软件包,Red Hat将发布这些软件包的升级版本。Red Hat已经发布了一个受影响的软件包清单,并公布了如果探测它们的说明。

Fedora项目的一名负责人在一个Fedora电子邮件列表中发布了一份安全公告称,上周发现一些服务器受到非法访问后,他们已经断开部分服务器的网络连接。

来源:赛迪网

From the "this isn't good news" files:

Servers for both Red Hat Enterprise Linux and Fedora Linux were compromised in recent weeks by some kind of illegal access. Neither project however is currently admitting than any of their software or users were in any way directly affected by the illegal access.
Fedora Project Leader Paul Frields wrote in a mailing list entry that:

    Last week we discovered that some Fedora servers were illegally accessed. The intrusion into the servers was quickly discovered, and the servers were taken offline.Security specialists and administrators have been working since then to analyze the intrusion and the extent of the compromise as well as reinstall Fedora systems.

On the Red Hat Enterprise side of things there is an OpenSSH update notification that contains (few) details about what happened.

    Last week Red Hat detected an intrusion on certain of its computer systems and took immediate action. While the investigation into the intrusion is on-going, our initial focus was to review and test the distribution channel we use with our customers, Red Hat Network (RHN) and its associated security measures. Based on these efforts, we remain highly confident that our systems and processes prevented the intrusion from compromising RHN or the content distributed via RHN and accordingly believe that customers who keep their systems updated using Red Hat Network are not at risk.

The fear in both cases is that an attacker could have somehow gained access and then created or compromised a security signing key used to distribute packages and updates.

As far as I can tell based on the analysis provided by Red Hat that's not the case and Red Hat and Fedora are being responsible and prudent by locking down system, analyzing everything and re-issuing keys.

仔细看来,应该有部分服务器已经被攻陷,部分软件可能遭到替换,建议适用最新更新红帽软件包的用户仔细查看受感染的软件包明细。排除隐患。

[ 本帖最后由 Send_linux 于 2008-8-23 21:57 编辑 ]
  发表评论 查看评论(共有条评论)
 
 


最新资讯更多>> 
· 专注于服务器操作系统的FreeBS..
· Mono 这只猴子招惹了谁?
· 分布式版本控制 Mercurial 1.3..
· 国内Firefox众生相
· CIH作者也是Linux热心者
· Ubuntu认为没有理由从默认安装..
· Linux内核新补丁发布:巧妙规避..
· Linux基金会:中国贡献代码少没..
· CU《开源时代》第十期(2009.0..
· 浅析龙芯的自由软件战略
论坛热点更多>> 
· 一个前同事:昨日(09,6,26)面..
· 简单的问题,请高手看下
· 请高人推荐一个Linux下的SSH..
· linux清空文件夹命令有吗
· 再见,Linux计算机!
· 大家推荐几个学习linux的论坛
· linux server 5 突然down机..
· redhat 5 企业版DNS配置问题
· 如何复制CDROM里的文件?
· x40换了ssd硬盘,好久没这么爽了
文档更新更多>> 
· GRUB故障修复 虚拟机fedora8
· Ubuntu 9.10 将采用 GRUB 2
· Surfraw: 在命令行下执行 WWW 搜索
· Linux将成首款支持USB3.0的操作系统
· RPM命令的常用参数
· phpMyAdmin下载、安装和使用入门
· uggs boots shop
· 虚拟文件系统:PROC
· Linux下解决三级域名不能访问的问题
· Windows 7 Vs. Linux——操作系统..
 
关于我们 | 联系方式 | 广告合作 | 诚聘英才 | 网站地图 | 友情链接 | 免费注册

Copyright © 2001-2008 ChinaUnix.net All Rights Reserved

感谢所有关心和支持过ChinaUnix的朋友们

京ICP证041476号