Уровень 0 · материалов: 4
В кластер входят документы об обнаружении и эксплуатации технических уязвимостей в программном обеспечении или инфраструктуре серверов, и не входят документы о социальном инжиниринге или общих политиках безопасности.
Общие признаки: компрометация безопасности, эксплуатация уязвимостей, утечка исходного кода, несанкционированный доступ
Группа выше: Обнаружение уязвимостей и взломы систем
Смысл: The text describes a 17-day security compromise of kernel.org servers by a trojan that provided root access and modified SSH files, which was discovered through a system anomaly by a developer.
Kernel.org servers were infected with a root-access trojan for 17 days before being detected by a developer noticing an unexpected Xnest error.
Смысл: The text describes the discovery of a widespread security vulnerability in the Subversion (SVN) version control system where hidden '.svn' folders were left accessible on production servers. This allowed the researchers to download source code from over 3,300 websites, including major Russian portals. The author provides technical solutions to fix the leak and shares statistics from their research.
Researchers discovered a common SVN misconfiguration that allowed them to access the source code of over 3,300 websites, including major Russian portals, and provide fixes for it.
Смысл: The text is a report about a session hijacking bug in Rambler's email service that allowed random access to user accounts, which was subsequently reported and fixed.
A security flaw in Rambler's registration and recovery pages allowed random session hijacking, but it was quickly reported and patched.
Смысл: A programmer exploited a critical GitHub vulnerability to commit code to the Ruby on Rails project after being ignored by maintainers, leading GitHub to implement a formal Responsible Disclosure policy.
Programmer Egor Khomyakov exploited a GitHub vulnerability to force attention on a bug, prompting GitHub to adopt a Responsible Disclosure policy.