Debian Development Machine ‘gluck’ Hacked!

The New Acunetix V12 Engine


Ah, I wonder what happened?

I’ve always been a great fan of Debian, all the way back into the early days of woody and backporting apt packages.

What a name too, gluck to me usually means g’luck or good luck ;)

Early this morning we discovered that someone had managed to compromise gluck.debian.org. We’ve taken the machine offline and are preparing to reinstall it. This means the following debian.org services are currently offline:

cvs, ddtp, lintian, people, popcon, planet, ports, release

Based on the results of our initial investigation we’ve locked down most other debian.org machines, limiting access to DSA only, until they can be fixed for what we suspect is the exploit used to compromise gluck.

We’re still investigating exactly what happened and the extent of the damage. We’ll post more info as soon as we reasonably can.

I wonder if it’s a 0-day for one of the services? I doubt it’s bad configuration?

If it’s 2.6 kernel though…I’ve noticed it’s pretty badly coded, but most of those exploits are local…they had to get in remotely somehow.

As a dev machine though it is possible a local user used a kernel exploit.

It could be speculated that it’s the Linux Kernel PRCTL Core Dump Handling Privilege Escalation Vulnerability.

Posted in: Exploits/Vulnerabilities, Linux Hacking

,


Latest Posts:


BDFProxy - Patch Binaries via MITM - BackdoorFactory + mitmProxy BDFProxy – Patch Binaries via MiTM – BackdoorFactory + mitmproxy
BDFProxy allows you to patch binaries via MiTM with The Backdoor Factory combined with mitmproxy enabling on the fly patching of binary downloads
Domained - Multi Tool Subdomain Enumeration Domained – Multi Tool Subdomain Enumeration
Domained is a multi tool subdomain enumeration tool that uses several subdomain enumeration tools and wordlists to create a unique list of subdomains.
Acunetix Vulnerability Scanner For Linux Now Available Acunetix Vulnerability Scanner For Linux Now Available
Acunetix Vulnerability Scanner For Linux is now available, now you get all of the functionality of Acunetix, with all of the dependability of Linux.
Gerix WiFi Cracker - Wireless 802.11 Hacking Tool With GUI Gerix WiFi Cracker – Wireless 802.11 Hacking Tool With GUI
Gerix WiFi cracker is an easy to use Wireless 802.11 Hacking Tool with a GUI, it was originally made to run on BackTrack and this version has been updated for Kali (2018.1).
Malcom - Malware Communication Analyzer Malcom – Malware Communication Analyzer
Malcom is a Malware Communication Analyzer designed to analyze a system's network communication using graphical representations of network traffic.
WepAttack - WLAN 802.11 WEP Key Hacking Tool WepAttack – WLAN 802.11 WEP Key Hacking Tool
WepAttack is a WLAN open source Linux WEP key hacking tool for breaking 802.11 WEP keys using a wordlist based dictionary attack.


Comments are closed.