Re: Debian servers "hacked"?

2003-11-21 Thread Ricardo Kustner
On Friday 21 November 2003 15:14, Thomas Sjögren wrote: > On Fri, Nov 21, 2003 at 02:17:52PM +0200, Johann Spies wrote: > > On Fri, Nov 21, 2003 at 12:38:50PM +0100, Thomas Sjögren wrote: > > > Anyone to shed some light over this > > There has been an announcement on the Debian-announce-list a few

Re: Debian servers "hacked"?

2003-11-21 Thread Lukas Ruf
-BEGIN PGP SIGNED MESSAGE- > Thomas Sj?gren <[EMAIL PROTECTED]> [2003-11-21 16:43]: > > On Fri, Nov 21, 2003 at 02:17:52PM +0200, Johann Spies wrote: > > On Fri, Nov 21, 2003 at 12:38:50PM +0100, Thomas Sjögren wrote: > > > Anyone to shed some light over this? > > > > There has been an ann

Re: Debian servers "hacked"?

2003-11-21 Thread Bueno
Sorry, wrong copy/paste http://cert.uni-stuttgart.de/files/fw/debian-security-20031121.txt is the right >>>> [Note: The original announcement didn't have a GnuPG >>>> signature.] On (21/11/03 14:15), Jan Wagner w

Re: Debian servers "hacked"?

2003-11-21 Thread Michael Stone
On Fri, Nov 21, 2003 at 01:32:22PM +0100, Thomas Sjögren wrote: Ok, so there's no manual auditing on services, processes, etc (on a daily basis) while the servers are running? Thank you for not starting wild unfounded rumors. If you don't have the facts it is unproductive to speculate wildly, espec

Re: Debian servers "hacked"?

2003-11-21 Thread Thomas Sjögren
On Fri, Nov 21, 2003 at 02:17:52PM +0200, Johann Spies wrote: > On Fri, Nov 21, 2003 at 12:38:50PM +0100, Thomas Sjögren wrote: > > Anyone to shed some light over this? > > There has been an announcement on the Debian-announce-list a few > minutes ago which clarifies the situation. I have asked M

Re: Debian servers "hacked"?

2003-11-21 Thread Bueno
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - The Debian Projecthttp://www.debian.org/ Some Debian Project machines compromised[EMAIL PROTECTED] November 21st, 2003 -

Re: Debian servers "hacked"?

2003-11-21 Thread Bueno
Sorry, wrong copy/paste http://cert.uni-stuttgart.de/files/fw/debian-security-20031121.txt is the right >>>> [Note: The original announcement didn't have a GnuPG >>>> signature.] On (21/11/03 14:15), Jan Wagner w

Re: Debian servers "hacked"?

2003-11-21 Thread Michael Stone
On Fri, Nov 21, 2003 at 01:32:22PM +0100, Thomas Sjögren wrote: Ok, so there's no manual auditing on services, processes, etc (on a daily basis) while the servers are running? Thank you for not starting wild unfounded rumors. If you don't have the facts it is unproductive to speculate wildly, e

Re: Debian servers "hacked"?

2003-11-21 Thread Thomas Sjögren
On Fri, Nov 21, 2003 at 02:17:52PM +0200, Johann Spies wrote: > On Fri, Nov 21, 2003 at 12:38:50PM +0100, Thomas Sjögren wrote: > > Anyone to shed some light over this? > > There has been an announcement on the Debian-announce-list a few > minutes ago which clarifies the situation. I have asked M

Re: Debian servers "hacked"?

2003-11-21 Thread Jan Wagner
On Friday 21 November 2003 13:58, Bueno wrote: > -BEGIN PGP SIGNED MESSAGE- > Hash: SHA1 > > - > The Debian Projecthttp://www.debian.org/ > Some Debian Project machines compromised

Re: Debian servers "hacked"?

2003-11-21 Thread Bueno
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - The Debian Projecthttp://www.debian.org/ Some Debian Project machines compromised[EMAIL PROTECTED] November 21st, 2003 -

Re: Debian servers "hacked"?

2003-11-21 Thread Michel Messerschmidt
On Fri, Nov 21, 2003 at 12:38:50PM +0100, Thomas Sjögren wrote: > Anyone to shed some light over this? Seems like there has been a message to debian-announce: http://cert.uni-stuttgart.de/ticker/article.php?mid=1167 I'm just wondering why I didn't received it ? -- Michel Messerschmidt

Re: Debian servers "hacked"?

2003-11-21 Thread Michele Baldessari
ease wait till an `official' release happens!" > http://article.gmane.org/gmane.linux.debian.user/117910 http://cert.uni-stuttgart.de/files/fw/debian-security-20031121.txt hth, Michele -- Poetry, the best of it, is lunar and is concerned with the essential insanities. Journalis

Re: Debian servers "hacked"?

2003-11-21 Thread Jan Wagner
On Friday 21 November 2003 13:58, Bueno wrote: > -BEGIN PGP SIGNED MESSAGE- > Hash: SHA1 > > - > The Debian Projecthttp://www.debian.org/ > Some Debian Project machines compromised

Re: Debian servers "hacked"?

2003-11-21 Thread Stephen Frost
re: http://cert.uni-stuttgart.de/files/fw/debian-security-20031121.txt And the person you're quoting from is a misinformed idiot. Stephen signature.asc Description: Digital signature

Re: Debian servers "hacked"?

2003-11-21 Thread Jens Mayer
st 2 days. Please do not apt-get > anything right now! Please wait till an `official' release happens!" > http://article.gmane.org/gmane.linux.debian.user/117910 > Server security mishap - you think?! http://cert.uni-stuttgart.de/files/fw/debian-security-20031121.txt Regar

Debian servers "hacked"?

2003-11-21 Thread Nils Ulltveit-Moe
Det går ubekreftede rykter om at Debian serverene skal ha blitt hacket: Vi vet ingenting om omfanget av dette. Mvh. Nils Thomas Sjögren writes: > Anyone to shed some light over this? > > "Someone has cracked all the servers of the Debian Project. There has > been a severe security mishap a

Re: Debian servers "hacked"?

2003-11-21 Thread Johann Spies
On Fri, Nov 21, 2003 at 12:38:50PM +0100, Thomas Sjögren wrote: > Anyone to shed some light over this? There has been an announcement on the Debian-announce-list a few minutes ago which clarifies the situation. I have asked Martin to publish the the announcement in this list also. Regards Johann

Re: Debian servers "hacked"?

2003-11-21 Thread Jan Wagner
On Friday 21 November 2003 13:32, Thomas Sjögren wrote: > On Fri, Nov 21, 2003 at 01:27:09PM +0100, Jan Wagner wrote: > > Thats ATM unknown. It seems, that nobody (except the bad boys) has access > > to the boxes. But there are ppl on the way to catch local access. Thats > > all I heared. > > Ok, s

Re: Debian servers "hacked"?

2003-11-21 Thread Tomasz Papszun
On Fri, 21 Nov 2003 at 12:38:50 +0100, Thomas Sjögren wrote: > Anyone to shed some light over this? > > "Someone has cracked all the servers of the Debian Project. There has > been a severe security mishap and guys should uninstall all stuff > downloaded and installed in the past 2 days. Please do

Re: Debian servers "hacked"?

2003-11-21 Thread Thomas Sjögren
On Fri, Nov 21, 2003 at 01:27:09PM +0100, Jan Wagner wrote: > Thats ATM unknown. It seems, that nobody (except the bad boys) has access to > the boxes. But there are ppl on the way to catch local access. Thats all I > heared. Ok, so there's no manual auditing on services, processes, etc (on a da

Re: Debian servers "hacked"?

2003-11-21 Thread Norbert Tretkowski
* Thomas Sjögren wrote: [...] > Server security mishap - you think?! http://luonnotar.infodrom.org/~joey/debian-announce.txt -- - nobse -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]

Re: Debian servers "hacked"?

2003-11-21 Thread Jan Wagner
On Friday 21 November 2003 13:18, Thomas Sjögren wrote: > On Fri, Nov 21, 2003 at 01:13:35PM +0100, Jan Wagner wrote: > > http://luonnotar.infodrom.org/~joey/debian-announce.txt > > Read that a minute ago, but what happended? Thats ATM unknown. It seems, that nobody (except the bad boys) has acces

Re: Debian servers "hacked"?

2003-11-21 Thread Michel Messerschmidt
On Fri, Nov 21, 2003 at 12:38:50PM +0100, Thomas Sjögren wrote: > Anyone to shed some light over this? Seems like there has been a message to debian-announce: http://cert.uni-stuttgart.de/ticker/article.php?mid=1167 I'm just wondering why I didn't received it ? -- Michel Messerschmidt

Re: Debian servers "hacked"?

2003-11-21 Thread Michele Baldessari
ease wait till an `official' release happens!" > http://article.gmane.org/gmane.linux.debian.user/117910 http://cert.uni-stuttgart.de/files/fw/debian-security-20031121.txt hth, Michele -- Poetry, the best of it, is lunar and is concerned with the essential insanities. Journalis

Re: Debian servers "hacked"?

2003-11-21 Thread Stephen Frost
re: http://cert.uni-stuttgart.de/files/fw/debian-security-20031121.txt And the person you're quoting from is a misinformed idiot. Stephen signature.asc Description: Digital signature

Re: Debian servers "hacked"?

2003-11-21 Thread Jens Mayer
st 2 days. Please do not apt-get > anything right now! Please wait till an `official' release happens!" > http://article.gmane.org/gmane.linux.debian.user/117910 > Server security mishap - you think?! http://cert.uni-stuttgart.de/files/fw/debian-security-20031121.txt Regar

Debian servers "hacked"?

2003-11-21 Thread Nils Ulltveit-Moe
Det går ubekreftede rykter om at Debian serverene skal ha blitt hacket: Vi vet ingenting om omfanget av dette. Mvh. Nils Thomas Sjögren writes: > Anyone to shed some light over this? > > "Someone has cracked all the servers of the Debian Project. There has > been a severe security mishap a

Re: Debian servers "hacked"?

2003-11-21 Thread Johann Spies
On Fri, Nov 21, 2003 at 12:38:50PM +0100, Thomas Sjögren wrote: > Anyone to shed some light over this? There has been an announcement on the Debian-announce-list a few minutes ago which clarifies the situation. I have asked Martin to publish the the announcement in this list also. Regards Johann

Re: Debian servers "hacked"?

2003-11-21 Thread Jan Wagner
On Friday 21 November 2003 13:32, Thomas Sjögren wrote: > On Fri, Nov 21, 2003 at 01:27:09PM +0100, Jan Wagner wrote: > > Thats ATM unknown. It seems, that nobody (except the bad boys) has access > > to the boxes. But there are ppl on the way to catch local access. Thats > > all I heared. > > Ok, s

Re: Debian servers "hacked"?

2003-11-21 Thread Tomasz Papszun
On Fri, 21 Nov 2003 at 12:38:50 +0100, Thomas Sjögren wrote: > Anyone to shed some light over this? > > "Someone has cracked all the servers of the Debian Project. There has > been a severe security mishap and guys should uninstall all stuff > downloaded and installed in the past 2 days. Please do

Re: Debian servers "hacked"?

2003-11-21 Thread Thomas Sjögren
On Fri, Nov 21, 2003 at 01:27:09PM +0100, Jan Wagner wrote: > Thats ATM unknown. It seems, that nobody (except the bad boys) has access to > the boxes. But there are ppl on the way to catch local access. Thats all I > heared. Ok, so there's no manual auditing on services, processes, etc (on a da

Re: Debian servers "hacked"?

2003-11-21 Thread Norbert Tretkowski
* Thomas Sjögren wrote: [...] > Server security mishap - you think?! http://luonnotar.infodrom.org/~joey/debian-announce.txt -- - nobse

Re: Debian servers "hacked"?

2003-11-21 Thread Jan Wagner
On Friday 21 November 2003 13:18, Thomas Sjögren wrote: > On Fri, Nov 21, 2003 at 01:13:35PM +0100, Jan Wagner wrote: > > http://luonnotar.infodrom.org/~joey/debian-announce.txt > > Read that a minute ago, but what happended? Thats ATM unknown. It seems, that nobody (except the bad boys) has acces

Re: Debian servers "hacked"?

2003-11-21 Thread Thomas Sjögren
On Fri, Nov 21, 2003 at 01:13:35PM +0100, Jan Wagner wrote: > http://luonnotar.infodrom.org/~joey/debian-announce.txt Read that a minute ago, but what happended? /Thomas -- == [EMAIL PROTECTED] | [EMAIL PROTECTED] == Encrypted e-mails preferred | GPG KeyID: 114AA85C -- signature.asc Descriptio

Re: Debian servers "hacked"?

2003-11-21 Thread Jan Wagner
On Friday 21 November 2003 12:38, Thomas Sjögren wrote: > Anyone to shed some light over this? > > "Someone has cracked all the servers of the Debian Project. There has > been a severe security mishap and guys should uninstall all stuff > downloaded and installed in the past 2 days. Please do not a

Re: Debian servers "hacked"?

2003-11-21 Thread Thomas Sjögren
On Fri, Nov 21, 2003 at 01:13:35PM +0100, Jan Wagner wrote: > http://luonnotar.infodrom.org/~joey/debian-announce.txt Read that a minute ago, but what happended? /Thomas -- == [EMAIL PROTECTED] | [EMAIL PROTECTED] == Encrypted e-mails preferred | GPG KeyID: 114AA85C -- signature.asc Descriptio

Re: Debian servers "hacked"?

2003-11-21 Thread Jan Wagner
On Friday 21 November 2003 12:38, Thomas Sjögren wrote: > Anyone to shed some light over this? > > "Someone has cracked all the servers of the Debian Project. There has > been a severe security mishap and guys should uninstall all stuff > downloaded and installed in the past 2 days. Please do not a

Debian servers "hacked"?

2003-11-21 Thread Thomas Sjögren
Anyone to shed some light over this? "Someone has cracked all the servers of the Debian Project. There has been a severe security mishap and guys should uninstall all stuff downloaded and installed in the past 2 days. Please do not apt-get anything right now! Please wait till an `official' release

Debian servers "hacked"?

2003-11-21 Thread Thomas Sjögren
Anyone to shed some light over this? "Someone has cracked all the servers of the Debian Project. There has been a severe security mishap and guys should uninstall all stuff downloaded and installed in the past 2 days. Please do not apt-get anything right now! Please wait till an `official' release