What other ways are there to download, apart from http and torrents?
Beware of hacked ISOs if you downloaded Linux Mint on February 20th
51–60 of 62 posts
Re: Beware of hacked ISOs if you downloaded Linux Mint on February 20th
#52Earlier quoted context omitted.
>It's pretty trivial to collide MD5 ... collisions=/=second-preimage attacks >SHA1/2 at least, but preferably a gpg signature would be much better. SHA1/2 isn't any better, you're never going to get hit by file corruption that magically also is a md5 collision.
How do you get hit by file corruption when downloading via TCP in 2016? I don't recall this ever happening to me.
Re: Beware of hacked ISOs if you downloaded Linux Mint on February 20th
#53Re: Beware of hacked ISOs if you downloaded Linux Mint on February 20th
#54I'll just leave this here forums.linuxmint.com pwd /root/hacked_distros/mint/var/www/forums.linuxmint.com forums.linuxmint.com cat config.php Perhaps the insanely secure db credentials had something to do with the breach? But what would I know.
Yo ryanlol, you made the press again except the pricks didn't mention your name: http://news.softpedia.com/news/linux-mint-website-hack-a-tim...
The fact that they're calling the bot "tsunami" just proves their incompetence. The bot isn't called tsunami, it's called kaiten and it's been open source for more than a decade.
https://packetstormsecurity.com/files/25575/kaiten.c.html
They also managed to confuse FTP and HTTP
>the hackers have only altered the man.cy [https://gist.github.com/Oweoqi/31239851e5b84dbba894] file, where they've added a new function called tsunami.
Doesn't look like they just added a new function called tsunami to me.
>Selling the forum's database for a meager $85 is a sign of their lack of vision. The group seems to have mishandled the entire hack, opting to distribute a silly IRC DDoS bot instead of more dangerous and lucrative malware like Bitcoin miners or banking trojans.
Stupid speculation by writer.
Linux Mint remains compromised despite the current events, it's rather unlikely that kaiten is used as a DDoS bot instead of just a stager to execute shell commands on the affected computers. The presence of DoS commands is meaningless, the only reason kaiten is still used today is because it runs everywhere so it seems fair to assume that that'd be why the attacker opted to just use it instead of writing their own. (No real benefit to that here)
Also, bitcoin mining stopped being lucrative ages ago.
edit: >One person seems to have bought the hackers' files and dumped the forum's config file on Hacker News discussions thread.
I neither bought nor sold the data.
Re: Beware of hacked ISOs if you downloaded Linux Mint on February 20th
#55Earlier quoted context omitted.
Yo ryanlol, you made the press again except the pricks didn't mention your name: http://news.softpedia.com/news/linux-mint-website-hack-a-tim...
I think calling softpedia "press" is an insult to every real journalist. The fact that they're calling the bot "tsunami" just proves their incompetence. The bot isn't called tsunami, it's called kaiten and it's been open source for more than a decade. https://packetstormsecurity.com/files/25575/kaiten.c.html They also managed to confuse FTP and HTTP >the hackers have only altered the man.cy [ https://gist.github.com/…
Re: Beware of hacked ISOs if you downloaded Linux Mint on February 20th
#56I was trying to download Linux securely a month or so ago. It's actually embarrassingly difficult to do. The only two distros that did it right (that I could find) are Debian and Alpine Linux. The rest (including Mint and Ubuntu) had hashes (usually MD5) or GPG keys served over HTTP.
Re: Beware of hacked ISOs if you downloaded Linux Mint on February 20th
#57I was trying to download Linux securely a month or so ago. It's actually embarrassingly difficult to do. The only two distros that did it right (that I could find) are Debian and Alpine Linux. The rest (including Mint and Ubuntu) had hashes (usually MD5) or GPG keys served over HTTP.
Re: Beware of hacked ISOs if you downloaded Linux Mint on February 20th
#58I was trying to download Linux securely a month or so ago. It's actually embarrassingly difficult to do. The only two distros that did it right (that I could find) are Debian and Alpine Linux. The rest (including Mint and Ubuntu) had hashes (usually MD5) or GPG keys served over HTTP.
Why is that a problem? If the hash is signed and the public key is trusted shouldn't that be secure?
Re: Beware of hacked ISOs if you downloaded Linux Mint on February 20th
#59Earlier quoted context omitted.
Why is that a problem? If the hash is signed and the public key is trusted shouldn't that be secure?
Because someone can do a man-in-the-middle attack and intercept the right hash and replace it with another one. And how do you verify that the public key is trusted for the first time?
Re: Beware of hacked ISOs if you downloaded Linux Mint on February 20th
#60I was trying to download Linux securely a month or so ago. It's actually embarrassingly difficult to do. The only two distros that did it right (that I could find) are Debian and Alpine Linux. The rest (including Mint and Ubuntu) had hashes (usually MD5) or GPG keys served over HTTP.
Are torrents more secure? I usually use the torrents option.