Welcome | Sign In
ECommerceTimes.com
Security

Hackers Get Under Red Hat's Skin

Print Version
E-Mail Article
Reprints
Hackers Get Under Red Hat's Skin

Open source software company Red Hat warned of a network intrusion that compromised some of the company's servers. Though Red Hat considered the advisory critical and issued updated versions of affected packages, it said that a worst-case scenario -- a hacker accessing servers used to sign Fedora or Red Hat applications distributed through their auto-update process -- did not come to pass.


How Much is 'Free' Costing You?
Learn how DaveRamsey.com saw a 567% uplift in ROI with Omniture. This complimentary guide and webinar cover the most important factors in selecting an analytics solution. Download Now.

Red Hat (NYSE: RHT) issued a security advisory Friday notifying customers that some of its servers were compromised last week due to a network attack. The company called the advisory critical and said it sent out the alert primarily for those who may obtain Red Hat binary packages via channels other than those of official Red Hat subscribers.

The servers -- for both the company's commercial products and free versions of Linux -- were breached; however, immediate action on the part of Red Hat prevented the attacker from gaining access to Red Hat Network (RHN) and its associated security measures, according to the company.

"This is a serious issue, rightly rated critical by Red Hat. And while there may not be cases of widespread exploitation of it, it does require prompt and direct response. I think Red Hat is doing that, and in the end I think this issue will be highlighted by the company's response," Jay Lyman, an analyst at The 451 Group, told the LinuxInsider.

Networking Nettles

The software company uses the RHN to disseminate fixes, patches, and updates of packages to Red Hat subscribers. The network is also used for several other functions, including provisioning and monitoring systems.

Last week, Red Hat detected an intrusion on certain of its computer systems, according to the security advisory. Following an immediate investigation, the company determined that the intruder was able to sign a small number of OpenSSH packages connected to Red Hat Linux Enterprise Linux 4 (i386 and x86-64 architectures only) and Red Hat Enterprise Linux 5 (x86-64 architecture only).

OpenSSH, created by the OpenBSD project, is a set of computer programs that provide encrypted communication sessions over a computer network using the SSH protocol.

As a precautionary measure, Red Hat released an updated version of the affected packages. The company has also published a list of the tampered packages and how to detect them.

The intrusion also affected Red Hat's Fedora servers, according to an e-mail Increase Customer Sales with Email Marketing -- Free Trial from VerticalResponse alert sent out by Paul Frields, project head.

The compromised servers are used for signing Fedora packages, but according to Frields, the attacker was not able to obtain the passphrase used to secure the Fedora package signing key. However, after reviewing the break-in, Fedora investigators determined that the passphrase was not used during the timeframe of the intrusion and that the passphrase is not stored on any Fedora servers.

As a result of the intrusion Frields said that the affected servers were taken offline and that the organization was using the outages as an opportunity to conduct upgrades to improve functionality and security. The work is ongoing, he warned, and he asked users to be patient.

As a precautionary measure, Frields said, Fedora will change its package signing key and is planning and has already begun executing additional safeguards.

The worst-case scenario for Red Hat would be if the intruder had compromised the servers used to sign Fedora or Red Hat applications distributed through their auto-update process, said Andrew Jaquith, an analyst at Yankee Group.

"That would be very bad indeed, although Red Hat says that no updates appear to have been compromised," he told the LinuxInsider.

On Guard

Last week's attack on Red Hat and Fedora servers are the second major issue for a Linux distributor in four months. Debian reported the discovery of a vulnerability in the OpenSSL package it had been distributing. The bug, found by Luciano Bello, was caused by the removal of a line of code.

The code was removed because it caused the Valgrind and Purify tools to produce warnings about the use of uninitialized data in any code linked to OpenSSL, Debian said.

"The Debian-OpenSSL issue was another significant security matter. Both illustrate some of the security concerns -- internal breaches or code corruption -- that may be more specific to open source," said The 451 Group's Lyman.

While these issues may heighten concerns or doubts about enterprise use of open source, it is limited to those already skeptical or unsure about deploying open source software, Lyman noted.

Though these issues might heighten concerns or doubles about enterprise use of open source software, "most enterprise users of Linux and open source software are coming to trust it and increase their use in general. I don't think this will impact that trend," he continued.

"Red Hat customers have cause to be aware and to be concerned, but with any enterprise-grade operating system, there are going to be security issues. This is why I believe it is the vendor's response that is most critical. Customers are being kept aware and updated with patches, so I would say the issue is being handled adequately," Lyman explained.

"The more serious issues seem to be on the Fedora side, and those users may be more tolerant of/prepared for such an issue since they are using a more leading-edge version of the OS, rather than the more stable and predictable enterprise RHEL (Red Hat Enterprise Linux)," he concluded.


Print Version E-Mail Article Reprints More by Walaika Haskins


More by Walaika Haskins

ZeeVee's Zinc Browser Gets Web TV Right
April 29, 2009
The Zinc Browser from ZeeVee updates the old Zviewer with tighter navigation and better catalog options. The finished application offers a great way to find TV shows and movies anywhere on the Web, regardless of whether they're hosted by Hulu, CBS, Netflix, Amazon's on-demand service or others.
Game Sales Sputter, 'GTA' Fails to Steal the Show
April 23, 2009
It may appear as though the video game industry is beginning to join the economy at large in its slump, as March numbers from NPD were less than encouraging. However, a year-over-year perspective is difficult due to the timing of game releases and holidays. Meanwhile, Take-Two hasn't seen much success in introducing its violent "GTA" series to the Nintendo DS.
Can Microsoft Win the Online Game?
April 16, 2009
Now that the major video game consoles have been on the market for two and a half years -- or more -- hardware sales have slowed considerably. Online services, however, still have room to grow. InStat says subscriber bases will take off in the coming years, and Microsoft's Xbox platform may come out the big winner.
Don't miss a story -- sign up for our FREE e-mail newsletters and view the latest headlines at a glance.
Tech News Flash [ View Sample ]
E-Commerce Minute [ View Sample ]
ECT News Network Weekly Newsletter [ View Sample ]
Shortcuts
ECT News Network Information
Reader Services
Corporate
ECT News Network