Published in News

OpenSUSE embarrassed by hack

by on09 January 2014

Depended on proprietary software

The openSUSE Forums were hijacked today by a Pakistani hacker who goes by handle H4x0r HuSsY. Apparently the hacker exploited the vulnerability in vBulletin 4.2.1 software which SUSE uses to host the forum. The problem is that the hack revealed that the openSUSE Forums were based on proprietary forum software.

The openSUSE team has denied that the users’ passwords were compromised by the hack.

"The credentials for your openSUSE login are not saved in our application databases as we use a single-sign-on system (Access Manager from NetIQ) for all our services. This is a completely separate system and it has not been compromised by this crack," the team said.

What the cracker reported as compromised passwords where indeed random automatically set strings that are in no way connected to your the passwords.

While it was good that none of the user data was compromised open sourcers are scratching their collective heads and wondering if the attack would have happened if the outfit had been eating its own dogfood and used some nice open source technologies.

Rate this item
(0 votes)