Featured Articles

Nvidia Shield 2 shows up in AnTuTu

Nvidia Shield 2 shows up in AnTuTu

Nvidia’s original Shield console launched last summer to mixed reviews. It went on sale in the US and so far Nvidia…

More...
AMD CSO John Byrne talks ARM

AMD CSO John Byrne talks ARM

We had a chance to talk about AMD’s upcoming products with John Byrne, Chief Sales Officer, AMD. We covered a number…

More...
AMD Chief Sales Officer thinks GPU leadership is critical

AMD Chief Sales Officer thinks GPU leadership is critical

We had a chance to talk to John Byrne who spent the last two years as Senior Vice President and Chief…

More...
OpenPlus One $299 5.5-inch Full HD phone

OpenPlus One $299 5.5-inch Full HD phone

OnePlus is one of the few small companies that might disrupt the Android phone market, dominated by giant outfits like Samsung.…

More...
KFA2 GTX 780 Ti Hall Of Fame reviewed

KFA2 GTX 780 Ti Hall Of Fame reviewed

KFA2 gained a lot of overclocking experience with the GTX 780 Hall of Fame (HOF), which we had a chance to…

More...
Frontpage Slideshow | Copyright © 2006-2010 orks, a business unit of Nuevvo Webware Ltd.
Thursday, 15 April 2010 11:39

Hackers scalp Apache

Written by Nick Farell

Image

Heap-um-big problems


Hackers have
broken into a server used by the Apache Software Foundation to keep track of software bugs.

While the attack did not compromise the open-source Web server's source code repository, they did get their paws on low-privilege accounts on another server used to maintain the people.apache.org Web site. Philip Gollucci, vice president of Apache infrastructure said that None of the source code was affected in any way.

Apparently the attack used a cross-site scripting bug to gain access. They then used a password-guessing attack to break into the Atlassian JIRA software used by Apache. After that it was a simple matter of installing a password stealing program and gaining full control of the machine. For a while they had access to two other programs hosted by Apache on the same server, the Confluence wiki program and Bugzilla.

The hackers had control of the server for three days between April 6 and April 9 The unidentified attackers broke into Apache's JIRA server on April 6 and had begun stealing user passwords by the time Apache administrators noticed the issue on April 9. It is the second time that the Apache Software Foundation has been hit by hackers. Last August intruders were able to break into the Minotaur server and run their owns scripts on Apache's Web site.

Nick Farell

E-mail: This e-mail address is being protected from spambots. You need JavaScript enabled to view it
blog comments powered by Disqus

To be able to post comments please log-in with Disqus

 

Facebook activity

Latest Commented Articles

Recent Comments