By Walaika Haskins LinuxInsider Part of the ECT News Network
08/25/08 1:44 PM PT
Open source software company Red Hat warned of a network intrusion that compromised some of the company's servers. Though Red Hat considered the advisory critical and issued updated versions of affected packages, it said that a worst-case scenario -- a hacker accessing servers used to sign Fedora or Red Hat applications distributed through their auto-update process -- did not come to pass.
eMarketer Whitepaper: Optimizing the E-Commerce Experience
From the Web to the Contact Center, are you prepared to proactively engage and keep your savvy customers? Read how e-commerce leaders are optimizing their sites with ratings, reviews, live help, Web analytics, mobile and more.
Red Hat (NYSE: RHT) issued a security advisory Friday notifying customers that some of its servers were compromised last week due to a network attack. The company called the advisory critical and said it sent out the alert primarily for those who may obtain Red Hat binary packages via channels other than those of official Red Hat subscribers.
The servers -- for both the company's commercial products and free versions of Linux -- were breached; however, immediate action on the part of Red Hat prevented the attacker from gaining access to Red Hat Network (RHN) and its associated security measures, according to the company.
"This is a serious issue, rightly rated critical by Red Hat. And while there may not be cases of widespread exploitation of it, it does require prompt and direct response. I think Red Hat is doing that, and in the end I think this issue will be highlighted by the company's response," Jay Lyman, an analyst at The 451 Group, told the LinuxInsider.
Networking Nettles
The software company uses the RHN to disseminate fixes, patches, and updates of packages to Red Hat subscribers. The network is also used for several other functions, including provisioning and monitoring systems.
Last week, Red Hat detected an intrusion on certain of its computer systems, according to the security advisory. Following an immediate investigation, the company determined that the intruder was able to sign a small number of OpenSSH packages connected to Red Hat Linux Enterprise Linux 4 (i386 and x86-64 architectures only) and Red Hat Enterprise Linux 5 (x86-64 architecture only).
OpenSSH, created by the OpenBSD project, is a set of computer programs that provide encrypted communication sessions over a computer network using the SSH protocol.
As a precautionary measure, Red Hat released an updated version of the affected packages. The company has also published a list of the tampered packages and how to detect them.
The intrusion also affected Red Hat's Fedora servers, according to an e-mail alert sent out by Paul Frields, project head.
The compromised servers are used for signing Fedora packages, but according to Frields, the attacker was not able to obtain the passphrase used to secure the Fedora package signing key. However, after reviewing the break-in, Fedora investigators determined that the passphrase was not used during the timeframe of the intrusion and that the passphrase is not stored on any Fedora servers.
As a result of the intrusion Frields said that the affected servers were taken offline and that the organization was using the outages as an opportunity to conduct upgrades to improve functionality and security. The work is ongoing, he warned, and he asked users to be patient.
As a precautionary measure, Frields said, Fedora will change its package signing key and is planning and has already begun executing additional safeguards.
The worst-case scenario for Red Hat would be if the intruder had compromised the servers used to sign Fedora or Red Hat applications distributed through their auto-update process, said Andrew Jaquith, an analyst at Yankee Group.
"That would be very bad indeed, although Red Hat says that no updates appear to have been compromised," he told the LinuxInsider.
On Guard
Last week's attack on Red Hat and Fedora servers are the second major issue for a Linux distributor in four months. Debian reported the discovery of a vulnerability in the OpenSSL package it had been distributing. The bug, found by Luciano Bello, was caused by the removal of a line of code.
The code was removed because it caused the Valgrind and Purify tools to produce warnings about the use of uninitialized data in any code linked to OpenSSL, Debian said.
"The Debian-OpenSSL issue was another significant security matter. Both illustrate some of the security concerns -- internal breaches or code corruption -- that may be more specific to open source," said The 451 Group's Lyman.
While these issues may heighten concerns or doubts about enterprise use of open source, it is limited to those already skeptical or unsure about deploying open source software, Lyman noted.
Though these issues might heighten concerns or doubles about enterprise use of open source software, "most enterprise users of Linux and open source software are coming to trust it and increase their use in general. I don't think this will impact that trend," he continued.
"Red Hat customers have cause to be aware and to be concerned, but with any enterprise-grade operating system, there are going to be security issues. This is why I believe it is the vendor's response that is most critical. Customers are being kept aware and updated with patches, so I would say the issue is being handled adequately," Lyman explained.
"The more serious issues seem to be on the Fedora side, and those users may be more tolerant of/prepared for such an issue since they are using a more leading-edge version of the OS, rather than the more stable and predictable enterprise RHEL (Red Hat Enterprise Linux)," he concluded.
Are VM Environments Open to Attack? July 22, 2008
Virtualization can bring about lower costs and fewer servers to maintain. Can it also open security holes? One should clearly never do anything with a virtual machine they wouldn't do with a physical machine. The nature of VMs, however, may bring about unique security concerns.
Related Stories
Microsoft, Novell Tag-Team Against Chinese Distros April 21, 2008
In an expansion of their existing partnership, Microsoft and Novell are taking on China together. The plan is for the two companies to go after companies that are using other Linux distributions and try to convert them to Suse Linux Enterprise.
Will Hardy Heron Shine Where Red Hat Fears to Tread? April 21, 2008
Red Hat's announcement that it would give up its pursuit of the consumer desktop with a Linux-based operating system started quite a buzz on the Linux blogs this week. The acceptance of Linux as a consumer alternative to Windows and Mac OS X is a perennial issue in the open source community.
The OSS Cure for What Ails Hospital IT April 11, 2008
Years ago, Florida Hospital in Orlando faced problems with its IT system, much of which relied on proprietary software. Innovative projects were abandoned due to high costs, and disaster recovery time was unacceptably long. So the hospital turned to open source. It was difficult at first, but officials say things are becoming easier as OSS goes more mainstream.
Related News Alerts
More by Walaika Haskins
ZeeVee's Zinc Browser Gets Web TV Right April 29, 2009
The Zinc Browser from ZeeVee updates the old Zviewer with tighter navigation and better catalog options. The finished application offers a great way to find TV shows and movies anywhere on the Web, regardless of whether they're hosted by Hulu, CBS, Netflix, Amazon's on-demand service or others.
Game Sales Sputter, 'GTA' Fails to Steal the Show April 23, 2009
It may appear as though the video game industry is beginning to join the economy at large in its slump, as March numbers from NPD were less than encouraging. However, a year-over-year perspective is difficult due to the timing of game releases and holidays. Meanwhile, Take-Two hasn't seen much success in introducing its violent "GTA" series to the Nintendo DS.
Can Microsoft Win the Online Game? April 16, 2009
Now that the major video game consoles have been on the market for two and a half years -- or more -- hardware sales have slowed considerably. Online services, however, still have room to grow. InStat says subscriber bases will take off in the coming years, and Microsoft's Xbox platform may come out the big winner.