Become a MacRumors Supporter for $50/year with no ads, ability to filter front page stories, and private forums.

997440

Cancelled
Original poster
Oct 11, 2015
938
664
.....
After some initial investigation, we were able to confirm there had been an exposure of data and shut down the Forums as a precautionary measure. Deeper investigation revealed that there was a known SQL injection vulnerability in the Forumrunner add-on in the Forums which had not yet been patched.
.....
We know the attacker was NOT able to gain access to any Ubuntu code repository or update mechanism.

We know the attacker was NOT able to gain access to valid user passwords.

We believe the attacker was NOT able to escalate past remote SQL read access to the Forums database on the Forums database servers.

We believe the attacker was NOT able to gain remote SQL write access to the Forums database.

We believe the attacker was NOT able to gain shell access on any of the Forums app or database servers.

We believe the attacker did NOT gain any access at all to the Forums front end servers.

We believe the attacker was NOT able to gain any access to any other Canonical or Ubuntu services.
.....
https://insights.ubuntu.com/2016/07/15/notice-of-security-breach-on-ubuntu-forums/
 
Register on MacRumors! This sidebar will go away, and you'll see fewer ads.