TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

Security Incident on FreeBSD Infrastructure

126 点作者 dous超过 12 年前

11 条评论

Zenst超过 12 年前
This is how you tell people about a security breach. Inform them soon as you know with what you know and assume the worst with your appraoch to restoring things.<p>Much respect and defineing the word professional for many.
meaty超过 12 年前
I have a couple of FreeBSD machines which pulled binary packages between those dates. I'm not overly worried. The packages have been removed and installed again from ports after a fresh portsnap dump and the systems have been verified with "freebsd-update IDS" against known good signatures. Any modified files were manually checked. I use MAC on each machine and pf up front on firewalls so I know what is going in and out as well.<p>The fact that these mechanisms are available is the reason I use such a system.<p>Also, if you consider any problems like this happening to a closed source vendor, you may never know it's happened. And don't tell me they don't do it as I've worked for a couple of companies that felt that burying security fuck ups was acceptable practice. It's why I don't work for them any more.
评论 #4798942 未加载
lifeguard超过 12 年前
Take note:<p>"We unfortunately cannot guarantee the integrity of any packages available for installation between 19th September 2012 and 11th November 2012, or of any ports compiled from trees obtained via any means other than through svn.freebsd.org or one of its mirrors. Although we have no evidence to suggest any tampering took place and believe such interference is unlikely, we have to recommend you consider reinstalling any machine from scratch, using trusted sources."
lhm超过 12 年前
I'm a bit suprised that the affected machines were powered off instead of just disconnected. Would that not make an audit more complicated?
评论 #4797926 未加载
评论 #4797923 未加载
评论 #4798027 未加载
darkf超过 12 年前
FreeBSD reports are always extremely professional, I love it.
0x0超过 12 年前
Interesting choice that some machines will not be reinstalled, only "thoroughly audited".
评论 #4797860 未加载
评论 #4797904 未加载
评论 #4797867 未加载
chmike超过 12 年前
Excuse the naive question, but how does one detect intrusion when using bi-key authentication ?
ladzoppelin超过 12 年前
How does one know the offsite repository's are clean if svnsync runs at set intervals? What if part of the attack was to make it look like happened at much late date/time after the malicious code was mirrored and backed up to the offsite repositories?
bulibuta超过 12 年前
Scary stuff.<p>Please use passwords for your keys and allow key access only to a small set of known IP addresses.<p>Also do share other security techniques you're using besides the ones above.
评论 #4798625 未加载
niels_olson超过 12 年前
End-user question: any word on how this affects my pc-bsd laptop recenttly updated to 9.1 RC-2?
DrCatbox超过 12 年前
They use SVN still?
评论 #4797890 未加载
评论 #4797944 未加载
评论 #4797900 未加载