Ubuntu Forum intrusion, user data leakage

Source: Internet
Author: User

Ubuntu Forum intrusion, user data leakage

Ubuntu Forums, the official forum of Ubuntu, was intruded by attackers, and more than 2 million user data, such as IP addresses, user names, and email addresses, were stolen. Canonical, responsible for Ubuntu development, explained the incident through an official blog: At UTC on January 1, July 14, it was notified that someone had obtained a copy of the Forum database. A preliminary investigation confirmed that the data was leaked, therefore, the Forum is immediately closed as a precaution. Further investigation found that the Forumrunner plug-in used by the Forum had a known SQL injection vulnerability and was not patched in time. Attackers can exploit this vulnerability to Download user-related databases, excluding passwords. The Forum uses Ubuntu Single Sign-on. The password field stored in the database is a random string.

 

Related Article

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.