Recommended Product
Network Security Audit Software
Network Security Audit Software and Computer Security Tools
  Learn More
 
 
  Network Security Software
Network Bandwidth Monitor

Network Bandwidth Monitor
NBMonitor displays real-time details about your network connections & bandwidth usage.

   
Network Access Monitoring

Network Access Monitoring
ShareAlarmPro monitors network access to shared folders and resources.

   
Product Key Finder
Product Key Finder

Product Key Explorer retrieves over 800 software product keys from network computers.
   
Network Shares Monitoring

Network Share Watcher
Monitors network folders permissions and identify shares which are violating company data access policy.

 
 

Network Security News

Free Software Foundation's software repository hacked

December 1 2010

The Web front end for a Free Software Foundation software repository remains down after the server it was hosted on was attacked last week.
The repository holds the pages for the organization's Gnu.org website, which the attackers altered last weekend. They also downloaded all the user names and encrypted passwords. None of the Gnu software projects on the server have been compromised as part of the attack, said Matt Lee, FSF's campaign manager.
As a precaution, the Savannah server's administrators eliminated any changes to the server contents since Nov. 23, a day before the first attack. Developers using the repositories can upload changes from their local copies, and as they are signed onto the system, they will be required to change their password.
According to the FSF, attackers breached the FSF server Nov. 24 by using SQL injection attacks against the Savane bug tracking application. The Savannah server, maintained by volunteers, holds the contents of the Gnu.org website in a CVS repository, as well as the Gnu-sponsored software projects. The server hosts both the savannah.gnu.org and savannah.nongnu.org domains, both of which are used to access the repositories.
The attackers obtained the user names and hashed passwords from a MySQL database and were able to create at least one new administrative account for the website, which allowed them to deface the Gnu.org home page.
The attackers also found a directory with PHP write access and ran a PHP reverse shell procedure to run root kits against the server. At this point however, the FSF believes they did not get root access to the server itself.
Savane is being rewritten and the developers are fixing the vulnerability, Lee said.
The FSF is not the only open-source software organization whose repositories have been compromised. Earlier this year, the Apache Software Foundation also had its site and passwords compromised.

View more news

 
  Most Popular
 
 
  Popular Searches
 

 

Sponsored Links
Network Security Auditor
Nsauditor is a complete networking utilities package that includes more than 45 network tools and utilities for network auditing, scanning,network connections monitoring and more. For more information, please visit:
www.nsauditor.com


Password Recovery Software
SpotAuditor is All-in-one password recovery program that offers administrators and users a comprehensive solution for recovering passwords and other critical business information saved in users' computers. For more information, please visit:
www.password-recovery-software.com

BlueAuditor - Monitor YourBluetooth Network
BlueAuditor detects and monitors Bluetooth devices in a wireless network and allows network administrators to audit wireless networks against security vulnerabilities associated with the use of Bluetooth devices. For more information, please visit:
nsauditor.com/bluetooth_network_scanner.html