Linux Mint forum hacked and distro altered

Options
wkleem
wkleem
Community Member

Every one registered in the Mint forum is advised to change their password.

http://m.slashdot.org/story/307701

Comments

  • wkleem
    wkleem
    Community Member
    Options

    A back door was added by the hacker to turn the Mint Distro into a botnet

  • AGAlumB
    AGAlumB
    1Password Alumni
    Options

    @wkleem: Indeed, I was saddened when I heard about the ISO tampering. People often move to Linux to escape malware and some of the other security issues common on other platforms, and this doesn't help anyone. It does sound like the window was relatively small, with relatively few installs being affected, but it's troubling nonetheless. :(

  • wkleem
    wkleem
    Community Member
    Options

    Hi Brent,

    From the sound of it, the actual Mint site was safe but the hackers used scripts to redirect downloads to a spoofed site that was indistinguishable from the Mint site.

  • AGAlumB
    AGAlumB
    1Password Alumni
    Options

    @wkleem: I may have misunderstood something, but I think if they were able to redirect links on the site to the modified ISOs, that suggests that the site itself was compromised in order to facilitate that...but regardless that's the fear of anyone who downloads software: that they aren't getting it from who they think they are. :scream:

  • wkleem
    wkleem
    Community Member
    Options

    You could be right @brenty. I was hasty in my posting. Wordpress, which is what the Mint Forum used, depending on the version, can be insecure.

  • AGAlumB
    AGAlumB
    1Password Alumni
    Options

    Unfortunately website vandalism is all too common. But it's when it leads to something like an OS installer being compromised that it can get really scary. :dizzy:

This discussion has been closed.