Cause of recent crack.

Questions about the project and the distribution - obviously no support questions here please
Post Reply
User avatar
RytronII
Level 4
Level 4
Posts: 363
Joined: Wed May 18, 2011 4:46 am
Location: Emerald Isle

Cause of recent crack.

Post by RytronII » Tue Mar 29, 2016 5:53 am

Hi.

Was the recent crack due to a Wordpress plugin issue or because a PHPbb config file was left accessible on the Internet?
Husse: "Don't fix it if it ain't broken, don't break it if you can't fix it."
Image

User avatar
Moem
Level 19
Level 19
Posts: 9347
Joined: Tue Nov 17, 2015 9:14 am
Location: The Netherlands
Contact:

Re: Cause of recent crack.

Post by Moem » Tue Mar 29, 2016 5:58 am

Which one are you asking about? The corruption of the download page, or the theft of forum user data?
Image

If your issue is solved, kindly indicate that by editing the first post in the topic, and adding [SOLVED] to the title. Thanks!

User avatar
RytronII
Level 4
Level 4
Posts: 363
Joined: Wed May 18, 2011 4:46 am
Location: Emerald Isle

Re: Cause of recent crack.

Post by RytronII » Tue Mar 29, 2016 6:08 am

M0em wrote:Which one are you asking about? The corruption of the download page, or the theft of forum user data?
Hi M0em.

I thought the same crack did the damage in both areas.

What was the exact cause of each attack?
Husse: "Don't fix it if it ain't broken, don't break it if you can't fix it."
Image

User avatar
Moem
Level 19
Level 19
Posts: 9347
Joined: Tue Nov 17, 2015 9:14 am
Location: The Netherlands
Contact:

Re: Cause of recent crack.

Post by Moem » Tue Mar 29, 2016 6:21 am

As far as I know, they did not happen at the same time; also, there is no phpBB on the download page and no Wordpress on the forum as far as I know, so I'm assuming there were two different causes / attack vectors. But I don't know more than that and I certainly don't know the exact cause of each attack. You may be able to find more information by reading the Linux Mint Blog.
Image

If your issue is solved, kindly indicate that by editing the first post in the topic, and adding [SOLVED] to the title. Thanks!

Habitual
Level 13
Level 13
Posts: 4870
Joined: Sun Nov 21, 2010 8:31 pm
Location: 0.0.0.0

Re: Cause of recent crack.

Post by Habitual » Tue Mar 29, 2016 7:12 am


User avatar
RytronII
Level 4
Level 4
Posts: 363
Joined: Wed May 18, 2011 4:46 am
Location: Emerald Isle

Re: Cause of recent crack.

Post by RytronII » Tue Mar 29, 2016 9:50 am

@Habitual @M0em
Can someone state the exact cause (maybe Clem can re-clarify it here). I don't fancy reading through all that blog when I just need a brief answer.
Husse: "Don't fix it if it ain't broken, don't break it if you can't fix it."
Image

Habitual
Level 13
Level 13
Posts: 4870
Joined: Sun Nov 21, 2010 8:31 pm
Location: 0.0.0.0

Re: Cause of recent crack.

Post by Habitual » Tue Mar 29, 2016 10:10 am

RytronII wrote:@Habitual @M0em
Can someone state the exact cause (maybe Clem can re-clarify it here). I don't fancy reading through all that blog when I just need a brief answer.
Sucks to be you.
What happened?
Hackers made a modified Linux Mint ISO, with a backdoor in it, and managed to hack our website to point to it.
is a brief answer.

and that is from Clem. So seeking additional authoritative sources for a reply is a waste of time.

User avatar
RytronII
Level 4
Level 4
Posts: 363
Joined: Wed May 18, 2011 4:46 am
Location: Emerald Isle

Re: Cause of recent crack.

Post by RytronII » Tue Mar 29, 2016 10:19 am

Habitual wrote: Sucks to be you.
That kind of comment is unhelpful.
Habitual wrote: What happened?
Hackers made a modified Linux Mint ISO, with a backdoor in it, and managed to hack our website to point to it.

is a brief answer.

and that is from Clem. So seeking additional authoritative sources for a reply is a waste of time.
It's not the answer I asked for - it says nothing about how the cracks occured. I think the users deserve to know the exact crack(s) that occurred.
Husse: "Don't fix it if it ain't broken, don't break it if you can't fix it."
Image

User avatar
Moem
Level 19
Level 19
Posts: 9347
Joined: Tue Nov 17, 2015 9:14 am
Location: The Netherlands
Contact:

Re: Cause of recent crack.

Post by Moem » Tue Mar 29, 2016 10:33 am

RytronII wrote:@Habitual @M0em
Can someone state the exact cause (maybe Clem can re-clarify it here). I don't fancy reading through all that blog when I just need a brief answer.
Possibly, but not me. I don't have that information. If Clem wants to share it here, I'm sure he will, but I would not count on him reading every thread in this forum.
Sorry, but since it's you who wants (not needs, let's be honest here) something, it looks like it may be you who's going to have to do the work.
Image

If your issue is solved, kindly indicate that by editing the first post in the topic, and adding [SOLVED] to the title. Thanks!

Habitual
Level 13
Level 13
Posts: 4870
Joined: Sun Nov 21, 2010 8:31 pm
Location: 0.0.0.0

Re: Cause of recent crack.

Post by Habitual » Tue Mar 29, 2016 10:44 am

RytronII wrote:That kind of comment is unhelpful.
You don't have "time" to read what the sole authoritative source has to say,
and I'm unhelpful?

I have spent more time on this subject today than you have.
And that is unfortunate.

Short version:
Old Wordpress.
Uploaded php shell.
Stole the db.
Modified links.

User avatar
RytronII
Level 4
Level 4
Posts: 363
Joined: Wed May 18, 2011 4:46 am
Location: Emerald Isle

Re: Cause of recent crack.

Post by RytronII » Tue Mar 29, 2016 2:08 pm

Habitual wrote:
RytronII wrote:That kind of comment is unhelpful.
You don't have "time" to read what the sole authoritative source has to say,
and I'm unhelpful?

I have spent more time on this subject today than you have.
And that is unfortunate.

Short version:
Old Wordpress.
Uploaded php shell.
Stole the db.
Modified links.
I did not call you unhelpful -- I stated a comment of yours was unhelpful.

No need to boast. I read through those blogs before but wanted a solid few lines or 1 paragraph on the exact details of the cause of the cracks. There was a lot of bloat in the blogs.

I know what happened i.e. the forum db was stolen and links being modified. Again, I did not ask about that -- I asked for the cause of the cracks. So it seems my first post was pretty much how the cracks happened.

There's no need to be so snarky.
Husse: "Don't fix it if it ain't broken, don't break it if you can't fix it."
Image

Habitual
Level 13
Level 13
Posts: 4870
Joined: Sun Nov 21, 2010 8:31 pm
Location: 0.0.0.0

Re: Cause of recent crack.

Post by Habitual » Tue Mar 29, 2016 2:41 pm

RytronII wrote:There's no need to be so snarky.
Snarky seems to be all you have time for.
RytronII wrote:I don't fancy reading through all that blog when I just need a brief answer.
In the total time you took to facilitate this whole subject, you could have had your answer, riki-tik

And
You're Welcome.

User avatar
RytronII
Level 4
Level 4
Posts: 363
Joined: Wed May 18, 2011 4:46 am
Location: Emerald Isle

Re: Cause of recent crack.

Post by RytronII » Wed Mar 30, 2016 7:47 am

Ok. I posted this thread in order to get a quick answer - I wrongly presumed that someone here would know the answer. I know now that I should not have posted it and instead just have thoroughly read through all the blogs about the cracks.

@Habitual You gave me no new info (but I do appreciate you at least trying). Also, you need to re-check what snarky means. :wink:
Peace and goodbye.
Husse: "Don't fix it if it ain't broken, don't break it if you can't fix it."
Image

Post Reply

Return to “Non-technical Questions”