<?xml version="1.0" encoding="utf-8" ?>
<rss version="2.0" xmlns:osnews="http://osnews.com/rss2#">
	<channel>
		<title>OSNews: </title>
		<link>http://www.osnews.com/story/20215/Red_Hat_Fedora_Servers_Infiltrated_By_Attackers</link>
		<description>Exploring the Future of Computing</description>
		<language>en-us</language>
		<copyright>Copyright 2001-2009, David Adams</copyright>
		<webMaster>adam+nospam@osnews.com</webMaster>
		<lastBuildDate>Mon, 09 Nov 2009 06:20:20 GMT</lastBuildDate>
		<image>
			<url>http://www.osnews.com/images/osnews.gif</url>
			<title>OSNews.com</title>
			<link>http://www.osnews.com</link>
		</image>
		<item>
			<title>Not entirely accurate</title>
			<link>http://osnews.com/thread?327944</link>
			<guid isPermaLink="true">http://osnews.com/thread?327944</guid>
			<description>Their package signing key was compromised and the intruders managed to get some OpenSSH packages signed. Combined with DNS poisoning this could be nasty.</description>
			<pubDate>Tue, 26 Aug 2008 14:07:00 GMT</pubDate>
			<author>donotreply@osnews.com (slight)</author>
			<category>Comments</category>
		</item>

		<item>
			<title>RE: Not entirely accurate</title>
			<link>http://osnews.com/thread?327957</link>
			<guid isPermaLink="true">http://osnews.com/thread?327957</guid>
			<description>It could have been bad if they had not caught it.  But it is pretty easily fixed as they just issue a point release with a new key and will overwrite the older version if you happened to get it.  Doesnt look like too many people actually downloaded it though.</description>
			<pubDate>Tue, 26 Aug 2008 14:59:00 GMT</pubDate>
			<author>donotreply@osnews.com (TechGeek)</author>
			<category>Comments</category>
		</item>

		<item>
			<title>Is pretty accurate</title>
			<link>http://osnews.com/thread?327961</link>
			<guid isPermaLink="true">http://osnews.com/thread?327961</guid>
			<description>&quot;Last week Red Hat detected an intrusion on certain of its computer systems and took immediate action.&quot;<br />
<br />
&quot;the intruder was able to sign a small<br />
number of OpenSSH packages&quot;<br />
<br />
If an outsider is able to gain Redhat's signing authority, then there is something wrong about how and where such critical data is stored there.  Redhat also mixes in a separate security fix in this errata to make the break in and internal problem seem trivial.</description>
			<pubDate>Tue, 26 Aug 2008 15:17:00 GMT</pubDate>
			<author>donotreply@osnews.com (libray)</author>
			<category>Comments</category>
		</item>

		<item>
			<title>RE: Not entirely accurate</title>
			<link>http://osnews.com/thread?327980</link>
			<guid isPermaLink="true">http://osnews.com/thread?327980</guid>
			<description>Actually, there were two separate attacks (although probably related) on the Red Hat and Fedora infrastructure servers.  The Red Hat attacker was able to sign some openssh packages.  My impression is that the intrusion was detected before the packages were pushed to users. But they did not compromise the private key since it is in a hardware device.<br />
<br />
The Fedora attacker was not able to sign any packages but did potentially compromise the signing key so they generated a new one. In both cases, they shut down the update service until everything was fixed. They also forced all the Fedora contributors to generate new certificates and upload new SSH keys.</description>
			<pubDate>Tue, 26 Aug 2008 16:31:00 GMT</pubDate>
			<author>donotreply@osnews.com (Znark)</author>
			<category>Comments</category>
		</item>

		<item>
			<title>Proven</title>
			<link>http://osnews.com/thread?327983</link>
			<guid isPermaLink="true">http://osnews.com/thread?327983</guid>
			<description>People were saying that Linux dont get attacked because of market share percentage. Seems they are doing just for the hell of it, linux Mint go his to as well recently.<br />
<br />
I think this testes the state of Linux repos and key system since it's pretty much very minor for their users. Disruption would be for the distro users only, not the whole linux community.</description>
			<pubDate>Tue, 26 Aug 2008 16:39:00 GMT</pubDate>
			<author>donotreply@osnews.com (SlackerJack)</author>
			<category>Comments</category>
		</item>

		<item>
			<title>RE: Proven</title>
			<link>http://osnews.com/thread?327986</link>
			<guid isPermaLink="true">http://osnews.com/thread?327986</guid>
			<description>The obscurity only applies to the desktop as I would suspect that the majority of webservers run Linux.<br />
<br />
Also, we do not have all the details yet. All it could be is a (now ex) disgruntled employee who had authorisation to work in these departments.<br />
<br />
Or it could be that a person who had authority had its account hijacked.<br />
<br />
Or it could be something else entirely.</description>
			<pubDate>Tue, 26 Aug 2008 16:49:00 GMT</pubDate>
			<author>donotreply@osnews.com (VistaUser)</author>
			<category>Comments</category>
		</item>

		<item>
			<title>RE[2]: Not entirely accurate</title>
			<link>http://osnews.com/thread?328050</link>
			<guid isPermaLink="true">http://osnews.com/thread?328050</guid>
			<description>I think the point is that it should never of happened. <br />
<br />
Prevention is always better than cure.</description>
			<pubDate>Tue, 26 Aug 2008 22:10:00 GMT</pubDate>
			<author>donotreply@osnews.com (flanque)</author>
			<category>Comments</category>
		</item>

		<item>
			<title>hacker</title>
			<link>http://osnews.com/thread?328054</link>
			<guid isPermaLink="true">http://osnews.com/thread?328054</guid>
			<description>I guess the hacker was good at it. Redhat should hire him.</description>
			<pubDate>Tue, 26 Aug 2008 22:25:00 GMT</pubDate>
			<author>donotreply@osnews.com (2501)</author>
			<category>Comments</category>
		</item>
	</channel>
</rss>
