Looks like something is going on again. Their website is down currently. [21-Feb 02:55 UTC]
Beware of hacked ISOs if you downloaded Linux Mint on February 20th
41–50 of 62 posts
Re: Beware of hacked ISOs if you downloaded Linux Mint on February 20th
#42Earlier quoted context omitted.
>It's pretty trivial to collide MD5 ... collisions=/=second-preimage attacks >SHA1/2 at least, but preferably a gpg signature would be much better. SHA1/2 isn't any better, you're never going to get hit by file corruption that magically also is a md5 collision.
How do you get hit by file corruption when downloading via TCP in 2016? I don't recall this ever happening to me.
-- TCP/IP Illustrated
Re: Beware of hacked ISOs if you downloaded Linux Mint on February 20th
#43I was trying to download Linux securely a month or so ago. It's actually embarrassingly difficult to do. The only two distros that did it right (that I could find) are Debian and Alpine Linux. The rest (including Mint and Ubuntu) had hashes (usually MD5) or GPG keys served over HTTP.
Re: Beware of hacked ISOs if you downloaded Linux Mint on February 20th
#44Re: Beware of hacked ISOs if you downloaded Linux Mint on February 20th
#45I am pretty sad they're posting MD5 sums of the correct images: It's pretty trivial to collide MD5 -- and when you've got an active attacker, this is something you should worry about. SHA1/2 at least, but preferably a gpg signature would be much better.
In the comments section... "You can find them at http://ftp.heanet.ie/pub/linuxmint.com/stable/17.3/ also along with signed sha256sums."
Re: Beware of hacked ISOs if you downloaded Linux Mint on February 20th
#46I was trying to download Linux securely a month or so ago. It's actually embarrassingly difficult to do. The only two distros that did it right (that I could find) are Debian and Alpine Linux. The rest (including Mint and Ubuntu) had hashes (usually MD5) or GPG keys served over HTTP.
Re: Beware of hacked ISOs if you downloaded Linux Mint on February 20th
#47I'll just leave this here forums.linuxmint.com pwd /root/hacked_distros/mint/var/www/forums.linuxmint.com forums.linuxmint.com cat config.php Perhaps the insanely secure db credentials had something to do with the breach? But what would I know.
You have an excellent point, but there's no reason to help attackers by giving them the credentials.
Re: Beware of hacked ISOs if you downloaded Linux Mint on February 20th
#48Earlier quoted context omitted.
You have an excellent point, but there's no reason to help attackers by giving them the credentials.
Indeed. Instead of `cat`, OP could've used `sha256sum` on the config.php to prove the authenticity of your report without exposing the site to even more attacks.
I strongly believe the users deserve to know just how incompetent these guys are, because next time it won't be some idiot swapping the iso links. It'll be someone slightly more competent that pushes a backdoored commit or gets into the apt repos, and then _every_ _single_ user will be affected...
Also, at the time of the posting the site was down. And it remains so.
Re: Beware of hacked ISOs if you downloaded Linux Mint on February 20th
#49It's somewhat disappointing that this blog article is served over HTTP, and it's impossible to access it via HTTPS. How do we know that these new MD5s are to be trusted?
Linux Mint doesn't seem to prioritize security in general. No TLS for ISOs, no easily spottable signatures for ISOs, marking security updates untrusted by default...
Re: Beware of hacked ISOs if you downloaded Linux Mint on February 20th
#50I'll just leave this here forums.linuxmint.com pwd /root/hacked_distros/mint/var/www/forums.linuxmint.com forums.linuxmint.com cat config.php Perhaps the insanely secure db credentials had something to do with the breach? But what would I know.
http://news.softpedia.com/news/linux-mint-website-hack-a-tim...