HZGN.COM
welcome to my space
X
Feng Shui | Graphic Design | Cosmetics | Causes and Organizations | Regulatory Compliance | Gadgets and Gizmos | Computer Forensics | Tools and Equipment | Related articles
Search:  
Welcome to:hzgn.com
NAVIGATION: Home >>

Apache Survives Server Crack Attack

Published by: mike 2009-01-06
The Apache Software Foundation (ASF), a group that assembled in 1999 to develop the Apache HTTP server and fuel open-source interests, made public Thursday that its server had been compromised by crackers. And with the revelation, the outfit professed why having an open-source model is advantageous in such serious situations.

The attack came from an unknown source May 17 and the server was taken offline right away so ASF administrators and security experts could deal with the situation. While not severe, the potential to cause damage was there as the server handles the public mail lists, Web services and most importantly, the source code repositories of all ASF projects.

ASF President Brian Behlendorf said "there is no evidence that any source or binary code was affected by the intrusion, and the integrity of all binary versions of ASF software has been explicitly verified," including the flagship Apache Web server.

Behlendorf and other experts were able to trace the cracker's steps to some degree. He said an Apache developer with a sourceforge.net account logged into a shell account at SourceForge, and then logged from there into his account at apache.org. The ssh client at SourceForge had been compromised to log outgoing names and passwords, so the cracker would have access to a shell on apache.org.

Linux & Windows: Both Good Enough, Report Claims @ WEB 2.0 JOURNAL::
Most SMBs and enterprise customers deploying Windows Server 2003 find its quality, performance and reliability equal to or better than Linux, according to the Yankee
http://www.web2journal.com/read/49112.htm
HOME
ddos Page 2 - dslreports.com::
Just standard HTTP requests to overload the Apache servers? SYN attack? the origination server and can be configured to block DoS attacks as they claim
http://www.dslreports.com/forum/r20312753-ddos~start=20
HOME
Upon failing to gain more privileges using an old installation of Bugzilla on apache.org, the cracker used a weakness in the ssh daemon (OpenSSH 2.2) to gain root privileges. Once root, s/he replaced the ssh client and server with versions designed to log names and passwords. Automated security audits caught the change, as well as a few other Trojaned executables the cracker had left behind.

At that point the organization shut down the server and performed a full audit, installed a fresh copy of the operating removed backdoors and negated passwords.

Behlendorf, who promised legal action where and if ever possible, stressed that ASF is working with other organizations to track the cracker, determine if additional comprises were made, and discern whether or not the ASF crack can be linked to previous intrusions at SourceForge and php.net.

ASF's leader also took the time to trumpet the advantages of open-source code models as opposed to the clenched-fist model employed by, well, Microsoft Corp.

"Through an extra verification step available to the ASF, the integrity of all source code repositories is being individually verified by developers," Behlendorf said in a public statement. "This is possible because ASF source code is distributed under an open-source license, and the source code is publicly and freely available. Therefore, the ASF repositories are being compared against the thousands of copies that have been distributed around the globe."

Behlendorf's suggestion is that the more developers that get a chance to verify the codes, the greater the chances are that additional information may be gleaned about the cracker and his or her methodology.

A list of verified modules will is available here. ASF asked that anyone with knowledge about the attack contact root@apache.org.


Motorola Intros Java Phones
ICANN's I Can't Attitude Alienating Internet Community

  • hello should have been in the liquid challenge
  • taking photos from a moving car
  • can you lens question
  • national pe 3057 flash instructions
  • cf card in eos d60
  • lens repair
  • temperature and noise
  • airport security and mrmory card
  • nikkor 28mm afd wont work on dslr
  • which compact flash card lexar problems
  • last two days
  • exposure latutude vs zones
  • photography material
  • helpful tutorials
  •  
  • newbie question inside
  • medium format question
  • wide angle conversion lenses
  • annoying problem with eos 350d
  • hassie users
  • weird black dot on my lens
  • watermark
  • how to make pictures soft
  • understanding scanning resolution
  • my old minolta 7000
  • techniques tips for taking indoor photos
  • dlsr manual focus
  • how do you know when your photos are valuable
  • #If you have any other info about this subject , Please add it free.#
    Your name:
    E-mail:
    Telphone:

    Your comments:


    If you have any other info about Apache Survives Server Crack Attack , Please add it free.
     Homepage | Add to favorites | Contact us | Exchange links | LOGIN | Site map | 
    Copyright© 2008 hzgn.com        Site made:CFZ