<?xml version='1.0' encoding='utf-8' ?>

<rss version='2.0' xmlns:lj='http://www.livejournal.org/rss/lj/1.0/' xmlns:atom10='http://www.w3.org/2005/Atom'>
<channel>
  <title>Linux4All</title>
  <link>https://linux4all.dreamwidth.org/</link>
  <description>Linux4All - Dreamwidth Studios</description>
  <lastBuildDate>Sun, 21 Feb 2016 11:32:51 GMT</lastBuildDate>
  <generator>LiveJournal / Dreamwidth Studios</generator>
  <lj:journal>linux4all</lj:journal>
  <lj:journaltype>community</lj:journaltype>
  <image>
    <url>https://v2.dreamwidth.org/9667/26390</url>
    <title>Linux4All</title>
    <link>https://linux4all.dreamwidth.org/</link>
    <width>81</width>
    <height>100</height>
  </image>

<item>
  <guid isPermaLink='true'>https://linux4all.dreamwidth.org/32202.html</guid>
  <pubDate>Sun, 21 Feb 2016 11:32:51 GMT</pubDate>
  <title>Linux Mint&apos;s download page compromised on Feb 20</title>
  <link>https://linux4all.dreamwidth.org/32202.html</link>
  <description>Posted by: &lt;span lj:user=&apos;moem&apos; style=&apos;white-space: nowrap;&apos; class=&apos;ljuser&apos;&gt;&lt;a href=&apos;https://moem.dreamwidth.org/profile&apos;&gt;&lt;img src=&apos;https://www.dreamwidth.org/img/silk/identity/user.png&apos; alt=&apos;[personal profile] &apos; width=&apos;17&apos; height=&apos;17&apos; style=&apos;vertical-align: text-bottom; border: 0; padding-right: 1px;&apos; /&gt;&lt;/a&gt;&lt;a href=&apos;https://moem.dreamwidth.org/&apos;&gt;&lt;b&gt;moem&lt;/b&gt;&lt;/a&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;em&gt;Clement Lefebvre writes on the &lt;/em&gt;&lt;a href=&quot;http://blog.linuxmint.com/?p=2994&quot;&gt;&lt;em&gt;Linux Mint Blog&lt;/em&gt;&lt;/a&gt;&lt;em&gt;:&lt;br /&gt;&lt;/em&gt;&lt;br /&gt;&lt;p&gt;&amp;quot;I&amp;rsquo;m sorry I have to come with bad news.&lt;/p&gt; &lt;p&gt;We were exposed to an intrusion today. It was brief and it shouldn&amp;rsquo;t  impact many people, but if it impacts you, it&amp;rsquo;s very important you read  the information below.&lt;/p&gt; &lt;p&gt;&lt;strong&gt;What happened?&lt;/strong&gt;&lt;/p&gt; &lt;p&gt;Hackers made a modified Linux Mint ISO, with a backdoor in it, and managed to hack our website to point to it.&lt;/p&gt; &lt;p&gt;&lt;strong&gt;Does this affect you?&lt;/strong&gt;&lt;/p&gt; &lt;p&gt;As far as we know, the only compromised edition was Linux Mint 17.3 Cinnamon edition.&lt;/p&gt; &lt;p&gt;If you downloaded another release or another edition, this does not  affect you. If you downloaded via torrents or via a direct HTTP link,  this doesn&amp;rsquo;t affect you either.&lt;/p&gt; &lt;p&gt;Finally, the situation happened today, so it should only impact people who downloaded this edition on February 20th.&lt;/p&gt; &lt;p&gt;&lt;strong&gt;How to check if your ISO is compromised?&lt;/strong&gt;&lt;/p&gt; &lt;p&gt;If you still have the ISO file, check its MD5 signature with the  command &amp;ldquo;md5sum yourfile.iso&amp;rdquo; (where yourfile.iso is the name of the  ISO).&lt;/p&gt; &lt;p&gt;The valid signatures are below:&lt;/p&gt; &lt;pre&gt;
6e7f7e03500747c6c3bfece2c9c8394f  linuxmint-17.3-cinnamon-32bit.iso
e71a2aad8b58605e906dbea444dc4983  linuxmint-17.3-cinnamon-64bit.iso
30fef1aa1134c5f3778c77c4417f7238  linuxmint-17.3-cinnamon-nocodecs-32bit.iso
3406350a87c201cdca0927b1bc7c2ccd  linuxmint-17.3-cinnamon-nocodecs-64bit.iso
df38af96e99726bb0a1ef3e5cd47563d  linuxmint-17.3-cinnamon-oem-64bit.iso
&lt;/pre&gt; &lt;p&gt;If you still have the burnt DVD or USB stick, boot a computer or a  virtual machine offline (turn off your router if in doubt) with it and  let it load the live session.&lt;/p&gt; &lt;p&gt;Once in the live session, if there is a file in /var/lib/man.cy, then this is an infected ISO.&lt;/p&gt; &lt;p&gt;&lt;strong&gt;What to do if you are affected?&lt;/strong&gt;&lt;/p&gt; &lt;p&gt;Delete the ISO. If you burnt it to DVD, trash the disc. If you burnt it to USB, format the stick.&lt;/p&gt; &lt;p&gt;If you installed this ISO on a computer:&lt;/p&gt; &lt;ul&gt;&lt;li&gt;Put the computer offline.&lt;/li&gt;&lt;li&gt;Backup your personal data, if any.&lt;/li&gt;&lt;li&gt;Reinstall the OS or format the partition.&lt;/li&gt;&lt;li&gt;Change your passwords for sensitive websites (for your email in particular).&lt;/li&gt;&lt;/ul&gt; &lt;p&gt;&lt;strong&gt;Is everything back to normal now?&lt;/strong&gt;&lt;/p&gt; &lt;p&gt;Not yet. We took the server down while we&amp;rsquo;re fixing the issue.&lt;/p&gt; &lt;p&gt;&lt;strong&gt;Who did that?&lt;/strong&gt;&lt;/p&gt; &lt;p&gt;The hacked ISOs are hosted on 5.104.175.212 and the backdoor connects to absentvodka.com.&lt;/p&gt; &lt;p&gt;Both lead to Sofia, Bulgaria, and the name of 3 people over there. We  don&amp;rsquo;t know their roles in this, but if we ask for an investigation,  this is where it will start.&lt;/p&gt; &lt;p&gt;What we don&amp;rsquo;t know is the motivation behind this attack. If more  efforts are made to attack our project and if the goal is to hurt us,  we&amp;rsquo;ll get in touch with authorities and security firms to confront the  people behind this.&lt;/p&gt; &lt;p&gt;If you&amp;rsquo;ve been affected by this, please do let us know.&amp;quot;&lt;/p&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;img src=&quot;https://www.dreamwidth.org/tools/commentcount?user=linux4all&amp;ditemid=32202&quot; width=&quot;30&quot; height=&quot;12&quot; alt=&quot;comment count unavailable&quot; style=&quot;vertical-align: middle;&quot;/&gt; comments</description>
  <comments>https://linux4all.dreamwidth.org/32202.html</comments>
  <category>hacked</category>
  <category>backdoor</category>
  <category>news</category>
  <category>linux</category>
  <category>mint</category>
  <lj:mood>annoyed</lj:mood>
  <lj:security>public</lj:security>
  <lj:poster>moem</lj:poster>
  <lj:reply-count>0</lj:reply-count>
</item>
</channel>
</rss>
