Live data from Hacker News

Canonical/Ubuntu have been under DDoS

status.canonical.com

51–60 of 76 posts

Re: Canonical/Ubuntu have been under DDoS

#52
post #2

Tinfoil hat mode: a competitor wants to exploit copy.fail on some ubuntu servers, and is DDoSing canonical so that they can't update and thus patch the vuln

If you can access AF_ALG on a server you don't need to do shenanigans like that. It's much easier to just find another bug and exploit that one instead. The copy.fail website is very silly, it is not a special bug. If anyone gets compromised by that vuln their node architecture was broken anyway, patching copy.fail doesn't help.

My mind immediately went to chaining this with another recent vulnerability in the Ninja Forms - File Upload plugin [0]

> This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.

So, upload and execute a script that loads Copy Fail and even if you're only executing as www-data or another restricted user that "can't" sudo -- suddenly, uid=0!

To repeat the refrain... I'm so tired.

[0] https://www.wordfence.com/blog/2026/04/attackers-actively-ex...

Re: Canonical/Ubuntu have been under DDoS

#58
post #51

Earlier quoted context omitted.

I did really well in Kindergarten, so I made it to the 22nd round.

They told me my grandpa was too dumb at round 47. I felt like I was close.

I got all the way to round 53, but it turned out that one of my semiaquatic tetrapod ancestors from the Carboniferous Period didn't perform on land as well as they would have liked, so that was it for me.

Re: Canonical/Ubuntu have been under DDoS

#60

While the timing with the copy.fail patches mentioned by a few comments here seems suspicious indeed, I have seen this repeating over the last few weeks: packages.ubuntu.com was hardly reachable on some days, causing apt-get to take forever to update the system. They have been struggling hard recently, it seems. Best of luck to the people having to deal with this mess on a holiday!

The point of coincidental timing with copy.fail patches is that by DDoSing an upgrade mechanism for one of most popular distributions, you extend the time window certain systems remain vulnerable in order to exploit them.
Post reply on HN