iTnews
  • Home
  • News
  • Technology
  • Security

Linux kernel repository compromised

By Darren Pauli
Sep 5 2011 1:59PM
Follow google news

Damage limited by git.

The secure shell (SSH) servers of the Linux kernel repository have been compromised and a trojan injected into the rc3.d startup file following a hack earlier this month.

Linux kernel repository compromised

The attack was undetected for at least 16 days and has sent members of the Linux kernel community scrambling to check for compromises.

Attackers gained root access on the Hera server, possibly through compromised user credentials, but it remains unknown how the root exploit was launched.

SSH files including openssh, openssh-server and openssh-clients were compromised and ran live.

All 448 users of kernel.org have been asked to change credentials and SSH keys.

A statement from kernel.org said alterations to Linux kernel files would be detected by version control modifications to SHA-1 hashes under the git distributed revision control system.

"The potential damage of cracking kernel.org is far less than typical software repositories," the statement said.

"For each of the nearly 40,000 files in the Linux kernel, a cryptographically secure SHA-1 hash is calculated to uniquely define the exact contents of that file.

"Git is designed so that the name of each version of the kernel depends upon the complete development history leading up to that version. Once it is published, it is not possible to change the old versions without it being noticed."

Administrators said they "believe that the source code repositories were unaffected" and had taken "steps to enhance security across the kernel.org infrastructure".

Chief kernel.org administrator John Hawley said in an email to developers that the hack may have caused recent instabilities in the kernel development.

"We are looking into everything," Hawley said. "I've not had what many would consider a 'good' day."

He called on developers to report suspicious findings that may be evidence of the intrusion.

"Verify your git trees and make sure things are correct."

Kernel contributor Jonathan Corbet said the hack was "disturbing and embassing".

"But I can also say that there is no need to worry about the integrity of the kernel source or of any other software hosted on the kernel.org systems," Corbet said.

"On the face of it, that would make kernel.org a tempting target for an attack. What self-respecting cracker wouldn’t want an opportunity to place some special code into the Linux kernel? Such code would, over time, find its way into millions of machines worldwide."

He said the Linux kernel was "well protected against that sort of attack.

"When we say that we know the kernel source has not been compromised on kernel.org, we really know it."

Telsyte senior analyst and Linux boffin Rodney Gedda said the attack was a reminder to keep systems up to date.

"This proves that how no matter how technical you are - and these guys know their stuff - everyone is vulnerable."

Add iTnews as your trusted source

Add iTnews As Your Trusted Source Add iTnews As Your Trusted Source
Got a news tip for our journalists? Share it with us anonymously here.

Copyright © SC Magazine, Australia

Tags:
hackingkernellinuxmalwaresecurity

Related Articles

  • AudiA6 crypto launderers arrested, network taken down by police AudiA6 crypto launderers arrested, network taken down by police
  • US charges suspected Russian hacker with facilitating cyber campaign US charges suspected Russian hacker with facilitating cyber campaign
  • Gov looks for upstream threat blocking by telcos, cloud operators Gov looks for upstream threat blocking by telcos, cloud operators
  • Federal Parliamentary Computer Network set for its "most significant" upgrade Federal Parliamentary Computer Network set for its "most significant" upgrade
Join our WhatsApp Channel

Partner Content

Intelligence × Trust: the equation that will decide Australia's AI winners
Promoted Content Intelligence × Trust: the equation that will decide Australia's AI winners
Agile isn’t the problem: why projects still fail, and what’s missing
Partner Content Agile isn’t the problem: why projects still fail, and what’s missing
AI is delivering business value today
Partner Content AI is delivering business value today
Why resilient communications are becoming critical infrastructure for modern enterprise IT
Promoted Content Why resilient communications are becoming critical infrastructure for modern enterprise IT

Sponsored Whitepapers

Are Australian organisations as cyber-ready as they think?
Are Australian organisations as cyber-ready as they think?
Are New Zealand organisations as cyber-ready as they think?
Are New Zealand organisations as cyber-ready as they think?
From visibility to execution:  Fixing the SaaS management gap
From visibility to execution: Fixing the SaaS management gap
When cyber risk has no clear owner: A practical guide for senior Australian business leaders
When cyber risk has no clear owner: A practical guide for senior Australian business leaders
Agile in the AI Era: why projects still fail
Agile in the AI Era: why projects still fail

Events

  • iTnews State of Security Breakfast iTnews State of Security Breakfast
  • iTnews State of Data & AI Breakfast iTnews State of Data & AI Breakfast
  • Forrester's AI Forum Sydney Forrester's AI Forum Sydney
  • The 2026 iAwards The 2026 iAwards
  • Integrate 2026 Integrate 2026
Share on Facebook Share on LinkedIn Share on Whatsapp Email A Friend

Most Read Articles

Services Australia describes fraud, debt-related machine learning use cases

Services Australia describes fraud, debt-related machine learning use cases

Anthropic opens Claude Mythos Preview AI program to Australia

Anthropic opens Claude Mythos Preview AI program to Australia

Defence says Palantir is "sandboxed" in its environment

Defence says Palantir is "sandboxed" in its environment

Researchers build self-replicating AI worm with BYO LLM

Researchers build self-replicating AI worm with BYO LLM

techpartner.news logo
Sydney-based AI-cloud waste startup raises $3m
Sydney-based AI-cloud waste startup raises $3m
Brennan uses NiCE to modernise its contact centre
Brennan uses NiCE to modernise its contact centre
Impact Awards: Tecala slashes customer response times for fintech IQumulate
Impact Awards: Tecala slashes customer response times for fintech IQumulate
Interactive introduces private cloud platform
Interactive introduces private cloud platform
Digital61 expands cybersecurity portfolio
Digital61 expands cybersecurity portfolio
All rights reserved. This material may not be published, broadcast, rewritten or redistributed in any form without prior authorisation.
Your use of this website constitutes acceptance of nextmedia's Privacy Policy and Terms & Conditions.