Announcement

Collapse
No announcement yet.

Linux MINT Warning!

Collapse
X
 
  • Filter
  • Time
  • Show
Clear All
new posts

    Linux MINT Warning!

    « Monthly News – January 2016 | All forums users should change their passwords. »
    Beware of hacked ISOs if you downloaded Linux Mint on February 20th!
    Written by Clem on Sunday, February 21st, 2016 @ 1:44 am | Main Topics

    I’m sorry I have to come with bad news.

    We were exposed to an intrusion today. It was brief and it shouldn’t impact many people, but if it impacts you, it’s very important you read the information below.

    What happened?

    Hackers made a modified Linux Mint ISO, with a backdoor in it, and managed to hack our website to point to it.

    Does this affect you?

    As far as we know, the only compromised edition was Linux Mint 17.3 Cinnamon edition.

    If you downloaded another release or another edition, this does not affect you. If you downloaded via torrents or via a direct HTTP link, this doesn’t affect you either.

    Finally, the situation happened today, so it should only impact people who downloaded this edition on February 20th.

    How to check if your ISO is compromised?

    If you still have the ISO file, check its MD5 signature with the command “md5sum yourfile.iso” (where yourfile.iso is the name of the ISO).

    The valid signatures are below:

    6e7f7e03500747c6c3bfece2c9c8394f linuxmint-17.3-cinnamon-32bit.iso
    e71a2aad8b58605e906dbea444dc4983 linuxmint-17.3-cinnamon-64bit.iso
    30fef1aa1134c5f3778c77c4417f7238 linuxmint-17.3-cinnamon-nocodecs-32bit.iso
    3406350a87c201cdca0927b1bc7c2ccd linuxmint-17.3-cinnamon-nocodecs-64bit.iso
    df38af96e99726bb0a1ef3e5cd47563d linuxmint-17.3-cinnamon-oem-64bit.iso

    If you still have the burnt DVD or USB stick, boot a computer or a virtual machine offline (turn off your router if in doubt) with it and let it load the live session.

    Once in the live session, if there is a file in /var/lib/man.cy, then this is an infected ISO.

    What to do if you are affected?

    Delete the ISO. If you burnt it to DVD, trash the disc. If you burnt it to USB, format the stick.

    If you installed this ISO on a computer:

    Put the computer offline.
    Backup your personal data, if any.
    Reinstall the OS or format the partition.
    Change your passwords for sensitive websites (for your email in particular).

    Is everything back to normal now?

    Not yet. We took the server down while we’re fixing the issue.

    Who did that?

    The hacked ISOs are hosted on 5.104.175.212 and the backdoor connects to absentvodka.com.

    Both lead to Sofia, Bulgaria, and the name of 3 people over there. We don’t know their roles in this, but if we ask for an investigation, this is where it will start.

    What we don’t know is the motivation behind this attack. If more efforts are made to attack our project and if the goal is to hurt us, we’ll get in touch with authorities and security firms to confront the people behind this.

    If you’ve been affected by this, please do let us know.
    http://blog.linuxmint.com/?p=2994

    #2
    Re: Linux MINT Warning!

    umm no. Post copypasta of the article with the link as a reference. I fixed it fer ya, but please in the future, post the text so we don't have to click. Makes news discussions much nicer.
    <--- Badcaps.net Founder

    Badcaps.net Services:

    Motherboard Repair Services

    ----------------------------------------------
    Badcaps.net Forum Members Folding Team
    http://folding.stanford.edu/
    Team : 49813
    Join in!!
    Team Stats

    Comment


      #3
      Re: Linux MINT Warning!

      More bad news ...

      http://blog.linuxmint.com/?p=3001

      It was confirmed that the forums database was compromised during the attack led against us yesterday and that the attackers acquired a copy of it. If you have an account on forums.linuxmint.com, please change your password on all sensitive websites as soon as possible.

      The database contains the following sensitive information:

      Your forums username
      An encrypted copy of your forums password
      Your email address
      Any personal information you might have put in your signature/profile/etc…
      Any personal information you might written on the forums (including private topics and private messages)
      People primarily at risk are people whose forums password is the same as their email password or as the password they use on popular or sensitive websites. Although the passwords cannot be decrypted, they can be brute-forced (found by trial) if they are simple enough or guessed if they relate to personal information.

      Out of precaution we recommend all forums users change their passwords.

      While changing your passwords, please start with your email password and do not use the same password on different websites.
      --- begin sig file ---

      If you are new to this forum, we can help a lot more if you please post clear focused pictures (max resolution 2000x2000 and 2MB) of your boards using the manage attachments button so they are hosted here. Information and picture clarity compositions should look like this post.

      We respectfully ask that you make some time and effort to read some of the guides available for basic troubleshooting. After you have read through them, then ask clarification questions or report your findings.

      Please do not post inline and offsite as they slow down the loading of pages.

      --- end sig file ---

      Comment


        #4
        Re: Linux MINT Warning!

        When downloading any distro, I always check every hash that is listed on the official website and I always download from the official site, never some 3rd part site.
        --- begin sig file ---

        If you are new to this forum, we can help a lot more if you please post clear focused pictures (max resolution 2000x2000 and 2MB) of your boards using the manage attachments button so they are hosted here. Information and picture clarity compositions should look like this post.

        We respectfully ask that you make some time and effort to read some of the guides available for basic troubleshooting. After you have read through them, then ask clarification questions or report your findings.

        Please do not post inline and offsite as they slow down the loading of pages.

        --- end sig file ---

        Comment


          #5
          Re: Linux MINT Warning!

          Originally posted by retiredcaps View Post
          When downloading any distro, I always check every hash that is listed on the official website and I always download from the official site, never some 3rd part site.
          Yeah, except the former can be broken by the hacker swapping the listed hash (or in more sophisticated situations, padding the file to spoof the hash) and the latter didn't matter since the official site was hacked.
          sigpic

          (Insert witty quote here)

          Comment


            #6
            Re: Linux MINT Warning!

            just download from an ftp mirror site.

            Comment


              #7
              Re: Linux MINT Warning!

              It would not surprise me one bit to find that Microsoft played a part in this hack.

              Comment


                #8
                Re: Linux MINT Warning!

                Originally posted by Sparkey55 View Post
                It would not surprise me one bit to find that Microsoft played a part in this hack.
                WTF does Microsoft have to do with this? seriously...

                Comment


                  #9
                  Re: Linux MINT Warning!

                  well they never could stand competition.

                  Comment


                    #10
                    Re: Linux MINT Warning!

                    Originally posted by shovenose View Post
                    WTF does Microsoft have to do with this? seriously...
                    You need to get out more often. The Evil Empire and Darth Vader wants the rest of us to join you on the Dark Side.

                    Comment


                      #11
                      Re: Linux MINT Warning!

                      Apparently the real world isn't scary enough for some folks and they feel some twisted need to make shit up to scare themselves and others with. There's a reason why evidence is required in order to accuse someone of crime.

                      Comment


                        #12
                        Re: Linux MINT Warning!

                        http://www.zdnet.com/article/hacker-...mint-backdoor/

                        A lone hacker who duped hundreds of users into downloading a version of Linux with a backdoor installed has revealed how it was done.

                        The hacker responsible, who goes by the name "Peace," told me in an encrypted chat on Sunday that a "few hundred" Linux Mint installs were under their control -- a significant portion of the thousand-plus downloads during the day.
                        --- begin sig file ---

                        If you are new to this forum, we can help a lot more if you please post clear focused pictures (max resolution 2000x2000 and 2MB) of your boards using the manage attachments button so they are hosted here. Information and picture clarity compositions should look like this post.

                        We respectfully ask that you make some time and effort to read some of the guides available for basic troubleshooting. After you have read through them, then ask clarification questions or report your findings.

                        Please do not post inline and offsite as they slow down the loading of pages.

                        --- end sig file ---

                        Comment


                          #13
                          Re: Linux MINT Warning!

                          Originally posted by SteveNielsen View Post
                          Apparently the real world isn't scary enough for some folks and they feel some twisted need to make shit up to scare themselves and others with. There's a reason why evidence is required in order to accuse someone of crime.
                          Microsoft Corp. is a front for Communist China. If what Microsoft and about a dozen other controlled Corps. has planned for the World is not enough to scare you then nothing else will.

                          Comment


                            #14
                            Re: Linux MINT Warning!

                            Originally posted by Sparkey55 View Post
                            It would not surprise me one bit to find that Microsoft played a part in this hack.
                            Not from Sofia, Bulgaria. Don't ask how I know this. Let's just make a blank statement and say that many parts of Eastern Europe are an endless PirateBay land. So if anything, this is the last place Microsoft will go for any kind of help.

                            Comment

                            Working...
                            X