Debian servers hacked?

2003-11-21 Thread Thomas Sjögren
Anyone to shed some light over this? Someone has cracked all the servers of the Debian Project. There has been a severe security mishap and guys should uninstall all stuff downloaded and installed in the past 2 days. Please do not apt-get anything right now! Please wait till an `official' release

Re: Debian servers hacked?

2003-11-21 Thread Jan Wagner
On Friday 21 November 2003 12:38, Thomas Sjögren wrote: Anyone to shed some light over this? Someone has cracked all the servers of the Debian Project. There has been a severe security mishap and guys should uninstall all stuff downloaded and installed in the past 2 days. Please do not

Re: Debian servers hacked?

2003-11-21 Thread Thomas Sjögren
On Fri, Nov 21, 2003 at 01:13:35PM +0100, Jan Wagner wrote: http://luonnotar.infodrom.org/~joey/debian-announce.txt Read that a minute ago, but what happended? /Thomas -- == [EMAIL PROTECTED] | [EMAIL PROTECTED] == Encrypted e-mails preferred | GPG KeyID: 114AA85C -- signature.asc

Re: Debian servers hacked?

2003-11-21 Thread Jan Wagner
On Friday 21 November 2003 13:18, Thomas Sjögren wrote: On Fri, Nov 21, 2003 at 01:13:35PM +0100, Jan Wagner wrote: http://luonnotar.infodrom.org/~joey/debian-announce.txt Read that a minute ago, but what happended? Thats ATM unknown. It seems, that nobody (except the bad boys) has access to

Re: Debian servers hacked?

2003-11-21 Thread Norbert Tretkowski
* Thomas Sjögren wrote: [...] Server security mishap - you think?! http://luonnotar.infodrom.org/~joey/debian-announce.txt -- - nobse -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of unsubscribe. Trouble? Contact [EMAIL PROTECTED]

Re: Debian servers hacked?

2003-11-21 Thread Thomas Sjögren
On Fri, Nov 21, 2003 at 01:27:09PM +0100, Jan Wagner wrote: Thats ATM unknown. It seems, that nobody (except the bad boys) has access to the boxes. But there are ppl on the way to catch local access. Thats all I heared. Ok, so there's no manual auditing on services, processes, etc (on a

Re: Debian servers hacked?

2003-11-21 Thread Tomasz Papszun
On Fri, 21 Nov 2003 at 12:38:50 +0100, Thomas Sjögren wrote: Anyone to shed some light over this? Someone has cracked all the servers of the Debian Project. There has been a severe security mishap and guys should uninstall all stuff downloaded and installed in the past 2 days. Please do not

Re: Debian servers hacked?

2003-11-21 Thread Jan Wagner
On Friday 21 November 2003 13:32, Thomas Sjögren wrote: On Fri, Nov 21, 2003 at 01:27:09PM +0100, Jan Wagner wrote: Thats ATM unknown. It seems, that nobody (except the bad boys) has access to the boxes. But there are ppl on the way to catch local access. Thats all I heared. Ok, so

Re: Debian servers hacked?

2003-11-21 Thread Johann Spies
On Fri, Nov 21, 2003 at 12:38:50PM +0100, Thomas Sjögren wrote: Anyone to shed some light over this? There has been an announcement on the Debian-announce-list a few minutes ago which clarifies the situation. I have asked Martin to publish the the announcement in this list also. Regards Johann

Debian servers hacked?

2003-11-21 Thread Nils Ulltveit-Moe
Det går ubekreftede rykter om at Debian serverene skal ha blitt hacket: Vi vet ingenting om omfanget av dette. Mvh. Nils Thomas Sjögren writes: Anyone to shed some light over this? Someone has cracked all the servers of the Debian Project. There has been a severe security mishap and

Re: Debian servers hacked?

2003-11-21 Thread Jens Mayer
not apt-get anything right now! Please wait till an `official' release happens! http://article.gmane.org/gmane.linux.debian.user/117910 Server security mishap - you think?! http://cert.uni-stuttgart.de/files/fw/debian-security-20031121.txt Regards, Jens -- It is better to be bow-legged than

Re: Debian servers hacked?

2003-11-21 Thread Stephen Frost
-security-20031121.txt And the person you're quoting from is a misinformed idiot. Stephen signature.asc Description: Digital signature

Re: Debian servers hacked?

2003-11-21 Thread Michele Baldessari
an `official' release happens! http://article.gmane.org/gmane.linux.debian.user/117910 http://cert.uni-stuttgart.de/files/fw/debian-security-20031121.txt hth, Michele -- Poetry, the best of it, is lunar and is concerned with the essential insanities. Journalism is solar (there are numerous newspapers named

Re: Debian servers hacked?

2003-11-21 Thread Michel Messerschmidt
On Fri, Nov 21, 2003 at 12:38:50PM +0100, Thomas Sjögren wrote: Anyone to shed some light over this? Seems like there has been a message to debian-announce: http://cert.uni-stuttgart.de/ticker/article.php?mid=1167 I'm just wondering why I didn't received it ? -- Michel Messerschmidt

Re: Debian servers hacked?

2003-11-21 Thread Michael Stone
On Fri, Nov 21, 2003 at 01:32:22PM +0100, Thomas Sjögren wrote: Ok, so there's no manual auditing on services, processes, etc (on a daily basis) while the servers are running? Thank you for not starting wild unfounded rumors. If you don't have the facts it is unproductive to speculate wildly,

Re: Debian servers hacked?

2003-11-21 Thread Bueno
Sorry, wrong copy/paste http://cert.uni-stuttgart.de/files/fw/debian-security-20031121.txt is the right [Note: The original announcement didn't have a GnuPG signature.] On (21/11/03 14:15), Jan Wagner wrote: On Friday 21 November 2003 13

Debian servers hacked?

2003-11-21 Thread Thomas Sjögren
Anyone to shed some light over this? Someone has cracked all the servers of the Debian Project. There has been a severe security mishap and guys should uninstall all stuff downloaded and installed in the past 2 days. Please do not apt-get anything right now! Please wait till an `official' release

Re: Debian servers hacked?

2003-11-21 Thread Jan Wagner
On Friday 21 November 2003 12:38, Thomas Sjögren wrote: Anyone to shed some light over this? Someone has cracked all the servers of the Debian Project. There has been a severe security mishap and guys should uninstall all stuff downloaded and installed in the past 2 days. Please do not

Re: Debian servers hacked?

2003-11-21 Thread Thomas Sjögren
On Fri, Nov 21, 2003 at 01:13:35PM +0100, Jan Wagner wrote: http://luonnotar.infodrom.org/~joey/debian-announce.txt Read that a minute ago, but what happended? /Thomas -- == [EMAIL PROTECTED] | [EMAIL PROTECTED] == Encrypted e-mails preferred | GPG KeyID: 114AA85C -- signature.asc

Re: Debian servers hacked?

2003-11-21 Thread Jan Wagner
On Friday 21 November 2003 13:18, Thomas Sjögren wrote: On Fri, Nov 21, 2003 at 01:13:35PM +0100, Jan Wagner wrote: http://luonnotar.infodrom.org/~joey/debian-announce.txt Read that a minute ago, but what happended? Thats ATM unknown. It seems, that nobody (except the bad boys) has access to

Re: Debian servers hacked?

2003-11-21 Thread Norbert Tretkowski
* Thomas Sjögren wrote: [...] Server security mishap - you think?! http://luonnotar.infodrom.org/~joey/debian-announce.txt -- - nobse

Re: Debian servers hacked?

2003-11-21 Thread Thomas Sjögren
On Fri, Nov 21, 2003 at 01:27:09PM +0100, Jan Wagner wrote: Thats ATM unknown. It seems, that nobody (except the bad boys) has access to the boxes. But there are ppl on the way to catch local access. Thats all I heared. Ok, so there's no manual auditing on services, processes, etc (on a

Re: Debian servers hacked?

2003-11-21 Thread Tomasz Papszun
On Fri, 21 Nov 2003 at 12:38:50 +0100, Thomas Sjögren wrote: Anyone to shed some light over this? Someone has cracked all the servers of the Debian Project. There has been a severe security mishap and guys should uninstall all stuff downloaded and installed in the past 2 days. Please do not

Re: Debian servers hacked?

2003-11-21 Thread Jan Wagner
On Friday 21 November 2003 13:32, Thomas Sjögren wrote: On Fri, Nov 21, 2003 at 01:27:09PM +0100, Jan Wagner wrote: Thats ATM unknown. It seems, that nobody (except the bad boys) has access to the boxes. But there are ppl on the way to catch local access. Thats all I heared. Ok, so

Re: Debian servers hacked?

2003-11-21 Thread Johann Spies
On Fri, Nov 21, 2003 at 12:38:50PM +0100, Thomas Sjögren wrote: Anyone to shed some light over this? There has been an announcement on the Debian-announce-list a few minutes ago which clarifies the situation. I have asked Martin to publish the the announcement in this list also. Regards Johann

Debian servers hacked?

2003-11-21 Thread Nils Ulltveit-Moe
Det går ubekreftede rykter om at Debian serverene skal ha blitt hacket: Vi vet ingenting om omfanget av dette. Mvh. Nils Thomas Sjögren writes: Anyone to shed some light over this? Someone has cracked all the servers of the Debian Project. There has been a severe security mishap and

Re: Debian servers hacked?

2003-11-21 Thread Jens Mayer
not apt-get anything right now! Please wait till an `official' release happens! http://article.gmane.org/gmane.linux.debian.user/117910 Server security mishap - you think?! http://cert.uni-stuttgart.de/files/fw/debian-security-20031121.txt Regards, Jens -- It is better to be bow-legged than

Re: Debian servers hacked?

2003-11-21 Thread Stephen Frost
-security-20031121.txt And the person you're quoting from is a misinformed idiot. Stephen signature.asc Description: Digital signature

Re: Debian servers hacked?

2003-11-21 Thread Michel Messerschmidt
On Fri, Nov 21, 2003 at 12:38:50PM +0100, Thomas Sjögren wrote: Anyone to shed some light over this? Seems like there has been a message to debian-announce: http://cert.uni-stuttgart.de/ticker/article.php?mid=1167 I'm just wondering why I didn't received it ? -- Michel Messerschmidt

Re: Debian servers hacked?

2003-11-21 Thread Jan Wagner
On Friday 21 November 2003 13:58, Bueno wrote: -BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - The Debian Projecthttp://www.debian.org/ Some Debian Project machines compromised

Re: Debian servers hacked?

2003-11-21 Thread Bueno
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - The Debian Projecthttp://www.debian.org/ Some Debian Project machines compromised[EMAIL PROTECTED] November 21st, 2003 -

Re: Debian servers hacked?

2003-11-21 Thread Thomas Sjögren
On Fri, Nov 21, 2003 at 02:17:52PM +0200, Johann Spies wrote: On Fri, Nov 21, 2003 at 12:38:50PM +0100, Thomas Sjögren wrote: Anyone to shed some light over this? There has been an announcement on the Debian-announce-list a few minutes ago which clarifies the situation. I have asked Martin

Re: Debian servers hacked?

2003-11-21 Thread Bueno
Sorry, wrong copy/paste http://cert.uni-stuttgart.de/files/fw/debian-security-20031121.txt is the right [Note: The original announcement didn't have a GnuPG signature.] On (21/11/03 14:15), Jan Wagner wrote: On Friday 21 November 2003 13

Re: Debian servers hacked?

2003-11-21 Thread Lukas Ruf
-BEGIN PGP SIGNED MESSAGE- Thomas Sj?gren [EMAIL PROTECTED] [2003-11-21 16:43]: On Fri, Nov 21, 2003 at 02:17:52PM +0200, Johann Spies wrote: On Fri, Nov 21, 2003 at 12:38:50PM +0100, Thomas Sjögren wrote: Anyone to shed some light over this? There has been an announcement on

Re: Debian servers hacked?

2003-11-21 Thread Ricardo Kustner
On Friday 21 November 2003 15:14, Thomas Sjögren wrote: On Fri, Nov 21, 2003 at 02:17:52PM +0200, Johann Spies wrote: On Fri, Nov 21, 2003 at 12:38:50PM +0100, Thomas Sjögren wrote: Anyone to shed some light over this There has been an announcement on the Debian-announce-list a few