{"id":660,"date":"2007-09-26T05:45:45","date_gmt":"2007-09-26T05:45:45","guid":{"rendered":"https:\/\/www.darknet.org.uk\/2007\/09\/gentoo-pulls-the-plug-after-getting-pwned\/"},"modified":"2015-09-09T19:39:55","modified_gmt":"2015-09-09T11:39:55","slug":"gentoo-pulls-the-plug-after-getting-pwned","status":"publish","type":"post","link":"https:\/\/www.darknet.org.uk\/2007\/09\/gentoo-pulls-the-plug-after-getting-pwned\/","title":{"rendered":"Gentoo Pulls the Plug after Getting Pwned"},"content":{"rendered":"

[ad]<\/p>\n

Gentoo Pulls the Plug after Getting Pwned<\/p>\n

Gentoo pulled quite a few of it\u2019s servers recently following the discovery of a fairly severe flaw in it\u2019s systems.<\/p>\n

Just to show that Linux systems aren\u2019t invulnerable and immune to all security issues.<\/p>\n

Ubuntu suffered quite heavily recently too, so don\u2019t assume just because you use Linux you\u2019re safe.<\/p>\n

Admins with the Gentoo Project say they have disconnected major parts of its website a week after discovering it could be vulnerable to a command injection attack that allows bad guys to remotely execute code on the machine.<\/p>\n

At time of writing, users trying to access Gentoo Archives and at least seven other areas of Gentoo.org got a message saying they were unavailable. Gentoo pulled the server hosting the sections \u201cto prevent further exploitation and to allow for forensic analysis,\u201d according to Gentoo\u2019s homepage.<\/p>\n

The words \u201cfurther exploitation\u201d and \u201cforensic analysis\u201d suggest the server was pwned, but Gentoo assures us the damage was minimal.<\/p><\/blockquote>\n

Not to say Linux is intrinsically unsafe either, you are definitely safer using Linux than Windows, especially if you don\u2019t spend all your time using root.<\/p>\n

Just be wary.<\/p>\n

Members intend to rebuild the server and will also perform a security audit on source code for packages.gentoo.org, which is the service containing the injection vulnerability. According to this advisory, the vulnerability allows the remote execution of code by attaching a semicolon to the end of the URL, immediately followed by the command an attacker wants to run. The bottom of the page will then display the output of that command.<\/p>\n

Gentoo\u2019s advisory comes a week after Ubuntu unplugged five of its eight production servers following the discovery they had been so badly compromised that they were being used to attack other sites. Turns out the systems, which were sponsored by Canonical and hosted by the community, were running an old version of Ubuntu. Tsk, tsk.<\/p><\/blockquote>\n

The irony is\u2026Gentoo servers are hosted on Ubuntu, old versions of Ubuntu with flaws!<\/p>\n

<\/p>\n

Source: The Register<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"

[ad] Gentoo Pulls the Plug after Getting Pwned Gentoo pulled quite a few of it\u2019s servers recently following the discovery of a fairly severe flaw in it\u2019s systems. Just to show that Linux systems aren\u2019t invulnerable and immune to all security issues. Ubuntu suffered quite heavily recently too, so don\u2019t assume just because you use […]<\/p>\n","protected":false},"author":25,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_seopress_robots_primary_cat":"","_seopress_titles_title":"","_seopress_titles_desc":"","_seopress_robots_index":"","_genesis_hide_title":false,"_genesis_hide_breadcrumbs":false,"_genesis_hide_singular_image":false,"_genesis_hide_footer_widgets":false,"_genesis_custom_body_class":"","_genesis_custom_post_class":"","_genesis_layout":"","footnotes":""},"categories":[6],"tags":[370,8859,450],"featured_image_src":null,"featured_image_src_square":null,"author_info":{"display_name":"Darknet","author_link":"https:\/\/www.darknet.org.uk\/author\/darknet\/"},"_links":{"self":[{"href":"https:\/\/www.darknet.org.uk\/wp-json\/wp\/v2\/posts\/660"}],"collection":[{"href":"https:\/\/www.darknet.org.uk\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.darknet.org.uk\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.darknet.org.uk\/wp-json\/wp\/v2\/users\/25"}],"replies":[{"embeddable":true,"href":"https:\/\/www.darknet.org.uk\/wp-json\/wp\/v2\/comments?post=660"}],"version-history":[{"count":0,"href":"https:\/\/www.darknet.org.uk\/wp-json\/wp\/v2\/posts\/660\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.darknet.org.uk\/wp-json\/wp\/v2\/media?parent=660"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.darknet.org.uk\/wp-json\/wp\/v2\/categories?post=660"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.darknet.org.uk\/wp-json\/wp\/v2\/tags?post=660"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}