1 |
- --------------------------------------------------------------------------- |
2 |
GENTOO LINUX SECURITY ANNOUNCEMENT 200312-01 |
3 |
- --------------------------------------------------------------------------- |
4 |
|
5 |
GLSA: 200312-01 |
6 |
summary: rsync.gentoo.org rotation server compromised |
7 |
severity: normal |
8 |
date: 2003-12-02 |
9 |
CVE: None |
10 |
exploit: remote |
11 |
|
12 |
DESCRIPTION: |
13 |
|
14 |
On December 2nd at approximately 03:45 UTC, one of the servers that makes up |
15 |
the rsync.gentoo.org rotation was compromised via a remote exploit. At this |
16 |
point, we are still performing forensic analysis. However, the compromised |
17 |
system had both an IDS and a file integrity checker installed and we have a |
18 |
very detailed forensic trail of what happened once the box was breached, so |
19 |
weare reasonably confident that the portage tree stored on that box |
20 |
wasunaffected. |
21 |
|
22 |
The attacker appears to have installed a rootkit and modified/deleted some |
23 |
files to cover their tracks, but left the server otherwise untouched. The box |
24 |
was in a compromised state for approximately one hour before it was |
25 |
discovered and shut down. During this time, approximately 20 users |
26 |
synchronized against the portage mirror stored on this box. The method used |
27 |
to gain access to the box remotely is still under investigation. We will |
28 |
release more details once we have ascertained the cause of the remote |
29 |
exploit. |
30 |
|
31 |
This box is not an official Gentoo infrastructure box and is instead donated |
32 |
by a sponsor. The box provides other services as well and the sponsor has |
33 |
requested that we not publicly identify the box at this time. Because the |
34 |
Gentoo part of this box appears to be unaffected by this exploit, we are |
35 |
currently honoring the sponsor's request. That said, if at any point, we |
36 |
determine that any file in the portage tree was modified in any way, we will |
37 |
release full details about the compromised server. |
38 |
|
39 |
SOLUTION: |
40 |
|
41 |
Again, based on the forensic analysis done so far, we are reasonably |
42 |
confident that no files within the Portage tree on the box were affected. |
43 |
However, the server has been removed from all rsync.*.gentoo.org rotations |
44 |
and will remain so until the forensic analysis has been completed and the box |
45 |
has been wiped and rebuilt. Thus, users preferring an extra level of security |
46 |
may ensure that they have a correct and accurate portage tree by running: |
47 |
|
48 |
emerge sync |
49 |
|
50 |
Which will perform a sync against another server and ensure that all files |
51 |
are up to date. |