bk99.de entertain the web since 1997

Gentoo takes servers offline because of security holes

Summary

In August 2007 Gentoo took several servers offline after a command injection hole had been discovered on packages.gentoo.org. The affected systems were examined forensically; whether any manipulation had taken place was unclear. According to Gentoo, packages and sources could not have been changed at any time, as the server only displayed information from the Portage tree.

Ideas

  • A command injection hole allowed a project server to be manipulated.
  • As a precaution, related servers were also switched off and examined.
  • Information server and package sources were separate, so packages were not affected.

Insights

  • Separating web services and package infrastructure limits the damage of a break-in.
  • Open communication about incidents builds trust, even when details are missing.

Facts

  • The hole was found on 7 August 2007.
  • Shortly before, several Ubuntu community servers had been taken offline after break-ins.

References

Critique

  • The report reproduces the project’s all-clear before the forensic investigation had been completed.

Recommendations

  • Strictly separate a project’s web services from the infrastructure for building and signing packages.
  • Verify packages via signatures so that a compromised server cannot slip in manipulated packages.

Read the original article

Search the Web Archive