{"id":288,"date":"2006-07-13T09:36:24","date_gmt":"2006-07-13T09:36:24","guid":{"rendered":"https:\/\/www.darknet.org.uk\/2006\/07\/debian-development-machine-gluck-hacked\/"},"modified":"2015-09-09T19:43:48","modified_gmt":"2015-09-09T11:43:48","slug":"debian-development-machine-gluck-hacked","status":"publish","type":"post","link":"https:\/\/www.darknet.org.uk\/2006\/07\/debian-development-machine-gluck-hacked\/","title":{"rendered":"Debian Development Machine ‘gluck’ Hacked!"},"content":{"rendered":"

[ad]<\/p>\n

Ah, I wonder what happened?<\/p>\n

I’ve always been a great fan of Debian, all the way back into the early days of woody and backporting apt packages.<\/p>\n

What a name too, gluck to me usually means g’luck or good luck ;)<\/p>\n

Early this morning we discovered that someone had managed to compromise gluck.debian.org. We’ve taken the machine offline and are preparing to reinstall it. This means the following debian.org services are currently offline:<\/p>\n

cvs, ddtp, lintian, people, popcon, planet, ports, release<\/code><\/p>\n

Based on the results of our initial investigation we’ve locked down most other debian.org machines, limiting access to DSA only, until they can be fixed for what we suspect is the exploit used to compromise gluck.<\/p>\n

We’re still investigating exactly what happened and the extent of the damage. We’ll post more info as soon as we reasonably can.<\/p><\/blockquote>\n

I wonder if it’s a 0-day for one of the services? I doubt it’s bad configuration?<\/p>\n

If it’s 2.6 kernel though…I’ve noticed it’s pretty badly coded, but most of those exploits are local…they had to get in remotely somehow.<\/p>\n

As a dev machine though it is possible a local user used a kernel exploit.<\/p>\n

<\/p>\n

It could be speculated that it’s the Linux Kernel PRCTL Core Dump Handling Privilege Escalation Vulnerability<\/a>.<\/p>\n","protected":false},"excerpt":{"rendered":"

[ad] Ah, I wonder what happened? I’ve always been a great fan of Debian, all the way back into the early days of woody and backporting apt packages. What a name too, gluck to me usually means g’luck or good luck ;) Early this morning we discovered that someone had managed to compromise gluck.debian.org. We’ve […]<\/p>\n","protected":false},"author":25,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_seopress_robots_primary_cat":"","_seopress_titles_title":"","_seopress_titles_desc":"","_seopress_robots_index":"","_genesis_hide_title":false,"_genesis_hide_breadcrumbs":false,"_genesis_hide_singular_image":false,"_genesis_hide_footer_widgets":false,"_genesis_custom_body_class":"","_genesis_custom_post_class":"","_genesis_layout":"","footnotes":""},"categories":[10,6],"tags":[863,8859],"featured_image_src":null,"featured_image_src_square":null,"author_info":{"display_name":"Darknet","author_link":"https:\/\/www.darknet.org.uk\/author\/darknet\/"},"_links":{"self":[{"href":"https:\/\/www.darknet.org.uk\/wp-json\/wp\/v2\/posts\/288"}],"collection":[{"href":"https:\/\/www.darknet.org.uk\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.darknet.org.uk\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.darknet.org.uk\/wp-json\/wp\/v2\/users\/25"}],"replies":[{"embeddable":true,"href":"https:\/\/www.darknet.org.uk\/wp-json\/wp\/v2\/comments?post=288"}],"version-history":[{"count":0,"href":"https:\/\/www.darknet.org.uk\/wp-json\/wp\/v2\/posts\/288\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.darknet.org.uk\/wp-json\/wp\/v2\/media?parent=288"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.darknet.org.uk\/wp-json\/wp\/v2\/categories?post=288"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.darknet.org.uk\/wp-json\/wp\/v2\/tags?post=288"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}