Canonical / Ubuntu user forums breeched!

VirtualLarry

No Lifer
Aug 25, 2001
56,571
10,206
126
https://distrowatch.com/weekly.php?issue=20160718#news
Canonical's Jane Silber has announced the Ubuntu community forums have been breached. The notice, which was posted early on July 15, indicates the attacker managed to gain access to the forum's database and access user information. "After some initial investigation, we were able to confirm there had been an exposure of data and shut down the forums as a precautionary measure. Deeper investigation revealed that there was a known SQL injection vulnerability in the Forumrunner add-on in the forums which had not yet been patched. The attacker had the ability to inject certain formatted SQL to the forums database on the forums database servers. This gave them the ability to read from any table but we believe they only ever read from the 'user' table. They used this access to download portions of the 'user' table which contained usernames, email addresses and IPs for two million users. No active passwords were accessed; the passwords stored in this table were random strings as the Ubuntu forums rely on Ubuntu Single Sign On for logins. The attacker did download these random strings (which were hashed and salted). The notice goes on to mention the attacker was not able to access Ubuntu's code or update repositories and could not access users' passwords.