compromised?

We've had some odd things happening, we don't know how yet, but it was odd.
To make sure things don't get worse we disabled the svn repository.

If you have an idea how to verify an svn repositories integrity, comments are open …

Comments

1

When will the svn be back? I want to install dionaea!

Cheers

jack
2010/02/15 17:07
2

Jack,

there's two possibilities:

(1) You send us your email address and we return to you a copy of the latest code we find in the svn. However, we cannot guarantee integrity, as we don't know if something has been modified by an attacker. So that version could be rootkitted.

(2) You wait until we checked the code and put the svn back online.

Let me know.

Tillmann
2010/02/15 21:09
3

Tillman,

Do you have a time frame of when the attack could have taken place? Maybe see when all files were modified, and compare file size?

If you don't mind can I get a copy of the trunk and I will see if I can find a way to quickly analyze it for a rootkit.

Thanks,

Zac
2010/02/16 03:44
4

So I guess that is why svn.carnivore.it is redirecting! Will keep checking to know when it is good to use again. Thanks.

Akash
2010/02/16 20:04
5

Here's my email address, Please send me the lastest dionaea srcs. Thanks in advance!

oMpa3a
2010/02/22 19:11
6

Here's my e-mail address… Please send me the latest sources and I'll keep it on a separate network until there's an update on possible compromises.

KjM
2010/02/23 17:54
7

Can you please send me the sources.

Akash
2010/02/23 20:11
8

For now, … http://dionaea.carnivore.it/tmp/



f7e7e6924fcfb441acc405795c8f3f33 dionaea-trunk.tar.bz2
db0ca02007963f294f45532d506a57e0 libemu-trunk.tar.bz2
f27712331ecd098932ad016c32f5a2f0 liblcfg-trunk.tar.bz2

Markus
2010/02/24 15:13
9

Cheers Markus!

Tom
2010/02/24 22:01
10

When will the svn be back? I want to install nepenthes!

emmy
2010/03/01 16:39
11

@emmy: Use the link Markus posted: http://dionaea.carnivore.it/tmp/

tom
2010/03/02 14:21
12

Could you plz put the dionaea virtualbox images in tmp folder!? thanx

twraymn
2010/03/03 11:37


2010/02/12/compromised.txt · Last modified: 2010/02/12 15:03 by common
chimeric.de = chi`s home Creative Commons License Valid CSS Driven by DokuWiki do yourself a favour and use a real browser - get firefox!! Recent changes RSS feed Valid XHTML 1.0