November 07, 2003 (IDG News Service) -- An attempt by an unknown attacker to plant a Trojan virus in the Linux kernel has been blocked.
On Wednesday, kernel developers discovered that a server hosting a copy of the Linux source code had been compromised and that a Linux kernel file had been changed to allow the attacker unauthorized access to operating systems built with the affected source code.
The machine in question, Kernel.bkbits.net, hosted a version of the Linux source code that was used by only a handful of Linux developers, according to Larry McVoy, a maintainer of the machine. "It's not a very tightly secured machine. It's more of a kernel developers' playground," he said.
McVoy didn't consider the attack to be significant because the exploit was quickly identified and because the site in question is used by such a small number of developers. The compromise was detected and corrected within 12 hours, and the compromised source was downloaded by, at most, a handful of developers, McVoy estimated.
The Kernel.org and Linux.bkbits.net sites that are used by the vast majority of Linux developers, including companies like Red Hat Inc. and SUSE Linux AG, weren't affected by the attack, McVoy said. Had an attacker been able to plant the exploit on those machines, it would have been "a dramatically bad thing," McVoy said.
The attack illustrates both the strengths and weaknesses of Linux development, said Linux creator Linus Torvalds in an e-mail interview. "To some degree, the fact that kernel development is pretty distributed and there isn't a single kernel tree that is 'the' tree means that there's not a single point of failure," he said.
"That also means that there are more endpoint machines," he said. "So arguably there are more targets for cracking."
Kernel.bkbits.net will be returned to service in a few days, when the machine has had its hard drive replaced and a new operating system installed with security fixes, McVoy said.
Reprinted with permission from For more news from IDG visit IDG.net Story copyright 2006 International Data Group. All rights reserved.
"I want; I mean I really want, an Apple MacBook Air. Mind you, I wouldn't kick a Lenovo ThinkPad X300..."
Read more...
"I'm very happy with my Linux desktop. To be precise, I'm very happy with SLED (SUSE Linux Enterprise Desktop) 10..."
Read more... Read more Linux posts or See all Blogs
Is Microsoft's Golden Age over? What are Gates' most memorable quotes? Find out in Computerworld's complete coverage of the end of the Bill Gates era at Microsoft.
Computerworld Technology Briefing: An open-source path to optimal virtualization
Download this Technology Briefing now! (Source: Novell/IBM/Intel) Virtualization is about a lot more than just lowering total cost of ownership. In fact users that have taken an open source path to virtualization have realized the additional, mission-critical benefit of markedly reduced IT complexity, as well as a more flexible infrastructure that is easier to change to meet shifting, often unpredictable business requirements.
Download this executive briefing
Long Tail Supplier Collaboration - What's In It For You?
Long Tail Supplier Collaboration - What's In It For You?
Download this webcast, free, compliments of Sterling Commerce
Go to the webcast
Virtualization Everywhere
Download this white paper, free, compliments of Citrix. (Source: Citrix) Adoption of virtualization is concentrated among large enterprises, while adoption by mid-sized companies has been much slower. For these companies, the cost and complexity of server virtualization solutions has been a barrier.
In this paper, we'll discuss how Citrix XenServer" provides simple, economical server virtualization for any size company. Download now!
HP StorageWorks EVA4400
Before now, midsize customers settled for either an expensive and complex array or low cost solution that lacked functionality. Now experience virtual storage with enterprise class functionality at an affordable price. View this product demo now
Are time constraints pressuring your development, QA, and support resources to cut corners on software quality? If so, your company's not alone. According to a commissioned study conducted by Forrester Consulting on behalf of BMC Software, "...problem resolution is a major time-sink for developers and a drain on the efficiency of application development and support."