Hacked Ubuntu forums, change passwords

Canonical, which develops the Ubuntu operating system, said in a statement today that two usernames, email addresses and IP addresses connected to the Ubuntu Forums were intercepted by an anonymous attacker.ubuntu

The attacker was able to exploit a vulnerability by executing SQL in an add-on used by the larger vBulletin forum software.

This gave the attacker access to the forum data, but according to the company managed to obtain limited user data.

The company statement highlights that there is no operating system code or data from application repositories, It also states that the attacker could not write data to the database or access shell, that he did not manage to gain access to any other service Canonical or Ubuntu.

After the breach, the servers were formatted, a new operating system was installed, new security measures, new ones and according to the company the forum software has been fully patched.

The statement added that although the forums use Ubuntu's single sign-on service, the passwords are hashed and salted. The statement does not indicate which hash algorithm has been used as some algorithms that are still in use (like MD5) are outdated and can break quite easily.

It's a good idea to change your passwords immediately and enable two-factor authentication.

iGuRu.gr The Best Technology Site in Greecefgns

every publication, directly to your inbox

Join the 2.087 registrants.

Written by giorgos

George still wonders what he's doing here ...

Leave a reply

Your email address is not published. Required fields are mentioned with *

Your message will not be published if:
1. Contains insulting, defamatory, racist, offensive or inappropriate comments.
2. Causes harm to minors.
3. It interferes with the privacy and individual and social rights of other users.
4. Advertises products or services or websites.
5. Contains personal information (address, phone, etc.).