Free Republic
Browse · Search
General/Chat
Topics · Post Article

Skip to comments.

Ubuntu Linux forums hacked!
BetaNews ^ | Published 10 hours ago (that's what it says!) | Brian Fagioli

Posted on 07/15/2016 6:57:53 PM PDT by Utilizer

There is a common misconception that all things Linux are bulletproof. The fact is, no software is infallible. When news of a Linux vulnerability hits, some Windows and Mac fans like to taunt users of the open source kernel. Sure, it might be in good fun, but it can negatively impact the Linux community's reputation -- a blemish, if you will.

Today, Canonical announces that the Ubuntu forums have been hacked. Keep in mind, this does not mean that the operating system has experienced a vulnerability or weakness. The only thing affected are the online forums that people use to discuss the OS. Still, such a hack is embarrassing, as it was caused by Canonical's failure to install a patch.

"There has been a security breach on the Ubuntu Forums site. We take information security and user privacy very seriously, follow a strict set of security practices and this incident has triggered a thorough investigation. Corrective action has been taken, and full service of the Forums has been restored. In the interest of transparency, we’d like to share the details of the breach and what steps have been taken. We apologize for the breach and ensuing inconvenience", says Jane Silber, Chief Executive Officer, Canonical Ltd.

(Excerpt) Read more at betanews.com ...


TOPICS: Business/Economy; Computers/Internet
KEYWORDS: cybersecurity; hacking; linux; security
Navigation: use the links below to view more comments.
first 1-2021-25 next last
Linux was not hacked. The forum was -in order to steal usernames and passwords.

Big difference between that and a 'doze user getting their personal machine hacked or getting a virus, adware, or other malware installed on their machine.

Or suddenly noticing that their computer is busily downloading or has already installed the "upgrade" known as Win10, like it or not!

BIG difference!

1 posted on 07/15/2016 6:57:53 PM PDT by Utilizer
[ Post Reply | Private Reply | View Replies]

To: Utilizer

And if the forum was using Linux as it’s platform?

Then it was hacked!


2 posted on 07/15/2016 7:03:01 PM PDT by unixfox (Abolish Slavery, Repeal the 16th Amendment)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Utilizer

someone realized the password was “Password”


3 posted on 07/15/2016 7:07:43 PM PDT by butlerweave
[ Post Reply | Private Reply | To 1 | View Replies]

To: unixfox

Possibly Ubuntu was hacked if it was running the server hosting the forum. More likely, the forum software was breached.


4 posted on 07/15/2016 7:11:40 PM PDT by ThunderSleeps (Stop obarma now! Stop the hussein - insane agenda!)
[ Post Reply | Private Reply | To 2 | View Replies]

To: unixfox

Then the forum website was hacked, not Linux itself.


5 posted on 07/15/2016 7:17:31 PM PDT by Utilizer (Bacon A'kbar! - In world today are only peaceful people, and the muzrims trying to kill them)
[ Post Reply | Private Reply | To 2 | View Replies]

To: ThunderSleeps

My guess is someone with admin privileges used an insecure or easily-guessed password and someone managed to determine it and gain access to the site. So yes, the forum security was breached for a time until they could reset the passwords.


6 posted on 07/15/2016 7:20:09 PM PDT by Utilizer (Bacon A'kbar! - In world today are only peaceful people, and the muzrims trying to kill them)
[ Post Reply | Private Reply | To 4 | View Replies]

To: unixfox

Or one can read the article...

“Deeper investigation revealed that there was a known SQL injection vulnerability in the Forumrunner add-on...”


7 posted on 07/15/2016 7:23:49 PM PDT by Mr. M.J.B.
[ Post Reply | Private Reply | To 2 | View Replies]

To: Utilizer

Brian’s middle name is Pasta E.


8 posted on 07/15/2016 7:24:11 PM PDT by Stentor (Free the Rosenbergs--Oh wait. Nevermind.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Utilizer

Or one can read the article...

“Deeper investigation revealed that there was a known SQL injection vulnerability in the Forumrunner add-on...”


9 posted on 07/15/2016 7:25:20 PM PDT by Mr. M.J.B.
[ Post Reply | Private Reply | To 6 | View Replies]

To: ThunderSleeps

Or one can read the article...

“Deeper investigation revealed that there was a known SQL injection vulnerability in the Forumrunner add-on...”


10 posted on 07/15/2016 7:26:02 PM PDT by Mr. M.J.B.
[ Post Reply | Private Reply | To 4 | View Replies]

To: Mr. M.J.B.

Really? It’s a Friday -do you really have to spoil My fun?

And I was so enjoying leading them on! :)


11 posted on 07/15/2016 7:31:33 PM PDT by Utilizer (Bacon A'kbar! - In world today are only peaceful people, and the muzrims trying to kill them)
[ Post Reply | Private Reply | To 9 | View Replies]

To: Utilizer

I heard that everyone downloading Linux was getting a copy of windows 10 Instead.


12 posted on 07/15/2016 7:33:19 PM PDT by Revel
[ Post Reply | Private Reply | To 1 | View Replies]

To: Mr. M.J.B.

I mean, you didn’t even give Me enough time to post the “It was Aliens” graphic!

Spoilsport. |b


13 posted on 07/15/2016 7:34:00 PM PDT by Utilizer (Bacon A'kbar! - In world today are only peaceful people, and the muzrims trying to kill them)
[ Post Reply | Private Reply | To 9 | View Replies]

To: Revel

*laugh!* Right, then, -that one made Me literally laugh out loud!

*grin* Great sense of humor, mate. :)


14 posted on 07/15/2016 7:35:38 PM PDT by Utilizer (Bacon A'kbar! - In world today are only peaceful people, and the muzrims trying to kill them)
[ Post Reply | Private Reply | To 12 | View Replies]

To: Utilizer

Sorry, the news the last 48 hours has been too much here.

I apologize for my snarkiness.

A good weekend.


15 posted on 07/15/2016 7:55:41 PM PDT by Mr. M.J.B.
[ Post Reply | Private Reply | To 11 | View Replies]

To: Mr. M.J.B.

There you go. Half the internet...hell way more than half...runs LAMP stacks with few problems. But they add something to PHP to make it easier to service mobile apps and bam. http://www.forumrunner.net/


16 posted on 07/15/2016 7:59:14 PM PDT by bigbob (The Hillary indictment will have to come from us.)
[ Post Reply | Private Reply | To 7 | View Replies]

To: Utilizer
The problem is almost certainly either the web forum software (probably written in PHP or similar) or a forum user with privilege and a weak password.

I'd be real surprised if this were a Linux kernel hack. Application software, database software, forum software,... sure.

In fact I'll bet a $20 donation to FR that it turns out to have nothing to do with the operating system itself.

17 posted on 07/15/2016 7:59:43 PM PDT by dayglored ("Listen. Strange women lying in ponds distributing swords is no basis for a system of government.")
[ Post Reply | Private Reply | To 1 | View Replies]

To: dayglored
I'd be real surprised if this were a Linux kernel hack. Application software, database software, forum software,... sure.

To be fair, on Windows or OS X it's almost never the kernel either. It's always some app, system service, browser, the Java stack, etc.

No way are the thousands of possible Linux open source packages built into the root filesystem image of the hundreds of Linux distro options any more secure than Windows or OS X applications. They're just less inviting targets due to lower consistent usage counts.

A full "OS" distribution per today's definitions is much more than just the kernel image, whether Windows, OS X or one of the many Linux variants.

18 posted on 07/15/2016 10:29:49 PM PDT by MCH
[ Post Reply | Private Reply | To 17 | View Replies]

To: MCH
Well, okay... sort of.

I see modern software systems as being loosely partitioned into four layers:

> ...thousands of possible Linux open source packages built into the root filesystem image of the hundreds of Linux distro options...

You must be thinking of the "complete desktop package" distros. Sure, Linux has a place on the desktop -- of about 1% of desktop users. The reality is that Linux is a server OS. And as such, those thousands of packages are in fact NOT "built into the root filesystem" of the servers.

Not arguing, just making a distinction:

Windows could not exist as a viable personal computer system without the millions of user applications that make it a useful personal computer for the vast majority of its users.

Linux has those applications available for its die-hard desktop users (I count myself among those, incidentally), but the vast majority of Linux "users" are the System Admins who run the servers.

So while I don't disagree with your assertion that today's full "OS" distributions have a lot of user-application stuff in them, in the case of Linux, most of that stuff is not in fact installed in the vast majority of installations.

19 posted on 07/15/2016 11:55:49 PM PDT by dayglored ("Listen. Strange women lying in ponds distributing swords is no basis for a system of government.")
[ Post Reply | Private Reply | To 18 | View Replies]

To: Mr. M.J.B.
“Deeper investigation revealed that there was a known SQL injection vulnerability in the Forumrunner add-on...”

Little Bobby Tables, yet again?


20 posted on 07/16/2016 12:04:35 AM PDT by cynwoody
[ Post Reply | Private Reply | To 9 | View Replies]


Navigation: use the links below to view more comments.
first 1-2021-25 next last

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
General/Chat
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson