Red Hat Fedora reveals details on intrusion attack | Internet News

Red Hat Fedora reveals details on intrusion attack

Mar 30, 2009
1 minute read

fedora-logo.png

From the

now we know

files:

Last August, Red Hat’s Fedora project announced that its servers had been compromised — now 6 months later (after an exhaustive investigation), Red Hat has revealed exactly what happened.

According to Red Hat Fedora Project Leader Paul Frields, the compromise did not come by way of any vulnerable software on the Fedora servers but rather by way of an SSH key that wasn’t properly secured. The SSH key belonged to a Fedora administrator and was used by the attacker to build modified version of openssh and rpm. That’s pretty serious – as it means the attacker could have potentially messed up all Fedora packages — but that’s not what happened in the end.

“The intruder did deploy the modified packages, and the modified SSH package may have captured passphrases for a short time,” Frields reported. “However, the investigation supports the conclusion that the modified packages were discovered before anyone accessed the system to sign any packages using the modified RPM package.”

Internet News Logo

InternetNews is a source of industry news and intelligence for IT professionals from all branches of the technology world. InternetNews focuses on helping professionals grow their knowledge base and authority in their field with the top news and trends in Software, IT Management, Networking & Communications, and Small Business.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.