SourceForge Down After Attack [Updated]
Animats writes "SourceForge, a hosting site for many open source projects, is down today. Management claims they were attacked: 'We detected a direct targeted attack that resulted in an exploit of several SourceForge.net servers, and have proactively shut down a handful of developer centric services to safeguard data and protect the majority of our services.' Currently, CVS and SVN access to source code, even for reading, is unavailable, and there is no announced restoration time." (SourceForge and Slashdot are both part of Geeknet, Inc.) Update: 01/27 22:17 GMT by T : Mark Ramm of SourceForge contributes an update and some clarification: the site is up, and SVN is available, though CVS isn't. There's also a follow-up post on the site's blog.
Now who would go and attack SourceForge? Microsoft? Oracle?
I just don't see why anyone would target an OSS repository.
One hopes they have checksums when they come back up to make sure people have slipped shit in.
What point is there to hitting SourceForge?
Funny may not give karma, but +5 Informative never made anyone snort coffee out their nose.
What the hell did sourceforge ever do to anyone?
I guess this could have been an attempt to spread some malware or something (by poisoning popular projects)?
Off topic: how many people actually download directly from sourceforge any more. I have to imagine the majority of users (even before the mass ubuntu influx) get their stuff second hand through their favorite distro’s repository these days. I know I haven’t been there with any regularity since my `ol slackware days *tugs pants up past waist*.
Whoever you are, out there, you're not a clever geek, you're just an asshole.
Do not mock my vision of impractical footwear
Can really free a portal for open-source software development be such a pebble in a shoe for someone? I can't think of none, *wink wink*, maybe someone who does not like stuff licensed under gpl, *nudge nudge*, oh noes... who can possibly believe in closedsource software as a future for the consumer out there? Oh, i dont know....
sourceforge.net
Since they took down SFTP access, presumably someone got their hands on passwords/the password database.
Emotions! In your brain!
Good thing Slashdot is still up and running!
Unless... it was replaced with an impostor with some bad design decisions!
http://www.exploit-db.com/papers/15823/
You would think that the authors of Ettercap, one of the most popular
whitehat pentesting tools, would know the basics of security.
Apparently they don't, or they just don't give a shit about what
happens to their users.
So, why is their website so insecure? Ettercap's message board is
hosted at Sourceforge, so they share a server with thousands of other
customers. Every single customer is able to execute commands and
access the other project directories. Pretty stupid, eh? You only need
to find one hole in one hosted site and you can access ALL the project
databases. Of course that isn't ALoR's fault, it's Sourceforge's
fault. Regardless, people who care about security and data integrity
wouldn't use such a shitty provider, would they?
I like the new layout, but I want the old icons back
grape - the GNU free, open source rape
The attacker(s) really must be either. Taking down a benign and beloved website which is frequented by a legion of genius coders is really asking for it.
I call it 'The Aristocrats'
Site seems to be up and working fine for me. All the way through to downloading code and executables.
There are so many stupid things in your post and subject line I don't even know where to start. Are all cool 7337 hackers as educated as you are?
Not at all. Many are as stupid as you.
This was posted on Full Disclosure 4 days ago. http://seclists.org/fulldisclosure/2011/Jan/424
Seems they left the backdoor open even after being notified.
This is the ultimate in bullying someone that doesn't deserve it. Kinda like the poor fat kid in middle school that got beat up by the entire football team because they didn't like the way I smelled.
Loading...
fish go m00 oh yes they do!
http://xkcd.com/72/
Somebody tried to fix the new Slashdot UI code - and it was also used by SourceForge?
Fandroids hate facts.
SVN may be up, but SVN browse code (via a web browser, what they call "ViewVC") is still failing.
Are all cool 7337 hackers as educated as you are?
No, only 7336 of them are.
"the site is up, and SVN is available, though CVS isn't" And nothing of value was lost.
I just received SPAM mail from my sourceforge account
username@users.sourceforge.net
Look at this girl who wants to get married and what people write about her on the forum http://pro-dota.com/forum/viewtopic.php?f=6&t=370
The hackers at least got hold of the users' details. There must be better places to get that info. Wonder what else they've gone through
> SVN is available, though CVS isn't
Perhaps this is a good time to consider upgrading to git, eh? Nothing like a server outage to remind you of the problems associated with a central repository, which you probably haven't even backed up.
Why would anyone attack an open source repository?
I like the new layout, but I want the old icons back
Don't fucking encourage them!
To have a right to do a thing is not at all the same as to be right in doing it
Some considerations about
http://extraexploit.blogspot.com/2011/01/sourceforge-entry-point-seems-still.html
As already written on fd mailing list I have post something more about this attack. Is interesting show how from a skeptical point of view of someone now finally is better understanding of the scope of this attack. My post about: "the sourceforge entry point seems still active" http://extraexploit.blogspot.com/2011/01/sourceforge-entry-point-seems-still.html and "some considerations on Ettercap source code repository breach" http://extraexploit.blogspot.com/2010/12/some-considerations-on-ettercap-source.html (about 1 month ago before the recently admission of sourceforge team). Regards.