Security Breach on the Ubuntu Forums

So apparently the ubuntu forums got hacked and someone made out with 2 million usernames, passwords and email adresses- ouch! Their site is currently down. Just posting as an FYI because their advice is to change your password if you have an account there and use it for multiple sites. 
Ubuntu Forums is down for maintenance
There has been a security breach on the Ubuntu Forums. The Canonical IS team is working hard as we speak to restore normal operations. This page will be updated regularly with progress reports.
What we know
Unfortunately the attackers have gotten every user's local username, password, and email address from the Ubuntu Forums database.
The passwords are not stored in plain text, they are stored as salted hashes. However, if you were using the same password as your Ubuntu Forums one on another service (such as email), you are strongly encouraged to change the password on the other service ASAP.
Ubuntu One, Launchpad and other Ubuntu/Canonical services are NOT affected by the breach.
Progress report
2013-07-20 2011UTC: Reports of defacement
2013-07-20 2015UTC: Site taken down, this splash page put in place while investigation continues.
If you're using Ubuntu and need technical support please see the following page for support:
Finding Help.
If you're looking for a place to discuss Ubuntu, in the meantime we encourage you to check out these sites:
Last edited by w201 (2013-07-22 08:59:58)

fukawi2 wrote:An unfortunate event for Canonical and the Ubuntu team. Glad to see the passwords were at least hashed, and with a salt.
Unfortunately md5 hashes even with salt are easily crackable. On the other hand, it's just a forum account and since they alerted people early, anyone foolish enough to use the same password elseware can change the other password on time.
One thing I disliked is that they haven't alerted people by email, at least I haven't got one yet. I got this information from various source, but many people (dormant accounts / less frequent users) are unlikely to know of it.
Last edited by x33a (2013-07-22 17:15:35)

Similar Messages

  • Does anyone know of the security breach on the iphone and what to down load to fix it?

    DOES ANYONE KNOW ANYTHING ABOUT THE SECURITY BREACH ON THE IPHONE AND IF YOU DO, WHAT DO YOU DOWN LOAD TO FIX IT?

    http://support.apple.com/kb/HT6147
    http://support.apple.com/kb/HT1222
    http://support.apple.com/kb/DL1723
    There is no security breach as such but rather a possibility of one dependant on a number of factors which may or may not be applicable to you and/or your usage.
    The recommendation is to update to the latest 7.0.6 update listed above. For iDevices such as the iPhone I would recommend doing this using iTunes rather than OTA. Tends to be more reliable that way.

  • Mail OS X Security breach...

    FYI.
    Apparently my Mail program was hacked. I'm no expert on security breaches but the story goes like this...
    Our ISP was acting up. I've verified w/4 others in the neighborhood (both Windows and Mac) using the same ISP who were experiencing the same issue. Would load some sites, some just wouldn't load. I've no idea if this is relative or not, but...
    The wife couldn't check her email because the Internet wouldn't connect. I looked at it, figured it was down, and went to bed. Next morning EVERY email in all 5 of my emails accounts was gone, except for my wife's account. Per the wife, she checked before she went to bed and all emails were gone in all accounts. She said there was an open window called Tiger Mail that said; If you'd like to continue to receive your email, click here. (Uh oh). She did and her inbox filled right up.
    Malware?
    I did a full erase/reformat regardless.

    See if you might have this malware redirecting DNS queries...
    http://macmegasite.com/node/3924
    How to fix...
    http://www.macosxhints.com/article.php?story=20071031114140862
    Nasty Nasty ! 1023.dmg...
    http://x704.net/bbs/viewtopic.php?f=12&t=2178
    http://www.dnschanger.com/

  • Security breach after updating FlashPlayer

    I just submitted a detailed description and request to Adobe security.  Briefly, I have been experiencing numerous security breaches in the form of spoofs asking for re-updates of software I have just updated, including FP and Java.  I may have been a victim of a drive by attack during one of my attempts to install the FP update.  I'm running FireFox on Win7 64bit.  I checked and I'm running the latest vsn of FP.
    Here is the URL for one of the latter:
    http://d11vdn9ox0j18d.cloudfront.net/html/pu/common.html?ait=Ad%20Info&u=http%3A%2F%2F1146 95url.directdisplayad.com%2Fcresults.jsp%3Fp%3D114695%26xyz%26ron%3Don%26ip%3D24.21.105.29 %26url%3Dhttp%253a%252f%252fphys.org%252fnews%252f2013-06-ultrasensitive-molybdenum-based- image-sensor.html%26aid%3D0%26subid%3D623%26context%3DAn%2Bultrasensitive%2Bmolybdenum-bas ed%2Bimage%2Bsensor%26mb%3D.003%26partnerMin%3D.003%26ronMin%3D.003%26selectedKeyword%3Dro n%26selectedListingId%3D7870593%26qs%3DJQwDFAMXaSFTVkVJRkRRSQ1ORURuXF5AW1QRc1pFBhAdEVReXRY QEWtaWkBbQ1Q8HgZPSEBSGw4aRBwRfVlcRFRRBiYcXkJXQEVcWVwHT0NuWUNAXF0Rc0gIBUQCGwdJHGhFHGZYD0ldV kInXwdESBRCUF5bEBkSMAtbFkoWTCoaXkNfAhEPK1NJVVUjTF4RSVdGYFwFAhEJB0cAHEYHVDI5UFYLAE8xDwQbHU1 GW1ZeEAdMMh0OGAkBYjxTMVQVGRBUWFYWERRqWksTBQEdd1ZQRUlJUg0dUxEPEWJcW0JKEFIpUwsGDQBRWg5LE0cEY Q8OAA0BTygHDRMNHwZHDAFMBBM1CgwdHARJIgAQV0sWHQcLC1kPUTsZSEMKAgV2CgACFBMVBB8PSEZPdltbAx4GBXY KUkNNRk1cSlwXSlZ2WgkCAwt_d1ZQRUlJK1xYXhcRGQ%3D%3D
       Many other suspicious URLs are from cloudfront as well.
      Has anyone else experienced these?
       What can I do to repair this obvious security problem?

    Never download Adobe updates from anywhere else than the Adobe.com website!
    There have been many reports of fake alerts to update Flash Player, Adobe Reader, and other Adobe products.  I don't know how you get them; either your system is infected with malware, or websites you visit are.

  • IMac security breach

    How can I check to see if my iMac has had a security breach?

    The only way you can be sure that the computer is not compromised is to erase at least the startup volume and restore it to something like the status quo ante. The easiest approach is to recover the entire system from a backup that predates the attack. Obviously, that's only practical if you know when the attack took place, and it was recent, and you have such a backup. You will lose all changes to data, such as email, that were made after the time of the snapshot. Some of those changes can be restored from a later backup.
    If you can't do that, then you should erase and install OS X. If you don't already have at least two complete, independent backups of all data, then you must make them first. One backup is not enough to be safe.
    When you restart after the installation, you'll be prompted to go through the initial setup process for a new computer. That’s when you transfer the data from a backup in Setup Assistant.
    Select only users in the Setup Assistant dialog—not Applications, Other files and folders, or Computer & Network Settings. Don't transfer the Guest account, if it was enabled.
    Reinstall third-party software from original media or fresh downloads—not from a backup, which may be contaminated.
    That being done, change all Internet passwords and check all financial accounts for unauthorized transactions. Do this after the system has been secured, not before.

  • IPad security breach

    We've discovered a serious security breach in the iPad 3 running iOS 5.1.1. We have no idea if this security breach exists in iOS 6.
    Take these steps to reproduce the security breach:
    1. Sign into the App Store from Settings > Store with an Apple ID.
    2. Go to the App Store and write a review for an app. Submit the review.
    3. Sign out of the App Store from Settings > Store
    4. Sign into the App Store with a DIFFERENT APPLE ID at Settings > Store
    5. Go to the App Store. You now have access to ALL THE REVIEWS written by BOTH the first Apple ID AND the second Apple ID, even though you're only signed in with the second Apple ID. If you go to any app and try to write a review, you will be able to edit & change the review, REGARDLESS of which Apple ID wrote the review. The App Store has basically granted you permission to ALL the reviews written by BOTH Apple IDs. If you sign out AGAIN of the App Store, the problem still doesn't fix itself. In fact, we can't figure out how to solve the problem, so we are currently dealing with this security hole on our iPad and it is unsolvable.

    For the original iPad (running 5.1.1), no. But devcies running 6 and 7 have updates.

  • When I close firefox "everything " is cleared! EXCEPT when I open it again and anything i have copied to the clipboard (paste icon) remains lit... I believe this can be a security breach because I clear everything when closing firefox !!

    I have my settings to clear everything when I close firefox ver 3.6.13. If I copy something to the clipboard, the Paste icon lights up so I can paste the text... which is normal.
    The problem is when I close the browser and everything is suppose to clear (history, etc) the PASTE Icon still lights up for me to paste again.
    This can be a security breach because I want everything cleared when closing the browser !!!
    The only way I can rid myself of this problem is to restart the computer... which clears the clipboard of the operatinging... which is absolutely normal as well.
    I should not have to restart the computer each time.
    Try It !!! type text in any box... then paste it by using the PASTE Icon
    CLEAR all your history, everything ... then close firefox
    Reopen the browser... and the PASTE Icon will light up

    I only had a few addons installed, I disabled Zone Alarm toolbar, View Source Chart 3.01. I also had 5 separate java console updates/addons, and I uninstalled all but the latest java console 6.0.21. All I have now is Roboform 6.9.98, Firebug 1.5.4, Java console 6.0.21, Java quick starter 1.0. So far, so good, the problem has not occurred today. I hope this is it, I will be more sure after a few days problem free. Thanks for the info.

  • Popup with the text "Security Breach" in Safari

    My son told me he saw a popup with the text "Security Breach" when visiting a website. He is concerned that his phone may be compromized. He is using Safari, iOS 6.0.1 on a iPhone 4S. The was a n OK button on the popup. He pressed it and the popup disappeared. Is there serious danger here?

    This may be caused by a problem with an add-on. Try the procedure in the [[Troubleshooting extensions and themes]] article.

  • This message [Ubuntu repositories or Mozilla download: " There is no Profile folder Could not initialize the application's security component. The most likely cause is problems with files in your application's profile directory....

    Ubuntu 11.04: I have been getting this message whenever I install Firefox from the repositories and downloading the tar file. I cannot use Firefox! " There is no Profile folder Could not initialize the application's security component. The most likely cause is problems with files in your application's profile directory. Please check that this directory has no read/write restrictions and your hard disk is not full or close to full. It is recommended that you exit the application and fix the problem. If you continue to use this session, you might see incorrect application behaviour when accessing security features."Firefox does not respond to any addresses or a google search. Indeed it responds to nothing. There is no Profile folder!

    Uninstalling Firefox on Linux
    * http://kb.mozillazine.org/Uninstalling_Firefox#On_Linux
    * http://kb.mozillazine.org/Installation_directory#Linux
    * Removing user profile data - http://kb.mozillazine.org/Uninstalling_Firefox#Removing_user_profile_data
    After all is done, Restart your system.
    Installing Firefox on Linux
    * https://support.mozilla.com/en-US/kb/Installing%20Firefox%20on%20Linux
    Check and tell if its working.

  • Cant seem to find the right forum, but I forget my security reset email info!

    Cant seem to find the right forum, but I forget my security reset email info! I want to download apps and music to my macbook, I cant because I forgot my security question's answers(6+ years ago) Also the security reset email they have is one that I have never seen before! I cant buy anything... on my new mac. IM STUCK!

    Then you are SoL until Apple's SNAFU is over, which could take another month for all God knows...

  • When I open Firefox the following alert appears: "Could not initialize the application's security component. The most likely cause is problems with files in your application's profile directory." There is a solution in the forum but only for Windows based

    When I open the application the following alert appears: "Could not initialize the application's security component. The most likely cause is problems with files in your application's profile directory." There is a solution on the support site but only for Windows-based Firefox, and I'm a Mac user. I have plenty of room on my hard disk.
    == This happened ==
    Every time Firefox opened
    == Two days ago, for no apparent reason.

    In Mac OS X v10.7, the $HOME/Library folder is a hidden folder.
    Open Finder and use one of these:
    * Go > Go To Folder (Shift-Command-G) and in the dialog type: ~/Library
    * Open the "Go" menu and hold down the Option key to make the Library appear
    You can also use this command in a Terminal window to remove the hidden flag.
    * Mac HD > Applications > Utilities > Terminal
    * chflags nohidden ~/Library

  • The Ubuntu Juggernaut

    who generously donated US$10 million to create the Ubuntu Foundation
    Taken from - THE UBUNTU JUGGERNAUT
    And what do we got?  I never knew this about Ubuntu.  People often compare us to gentoo, which is a massive distro, and the other often mentioned distros are Slack and Ubuntu,  If Ubuntu have THAT much money to throw at a problem and Slackware has basically YEARS of topflight experience I reckon we are coming along pretty well!
    I'd also like to note that money does not equal a good distro, I mean, look at Microsoft, but it certainly doesn't hurt.
    Lets look at forum membership:
    Ubuntu: 46,705 - with 152 MEMBERS online when I looked and 79,357 THREADS
    gentoo: 97,581 - with 51 MEMBERS online when I looked and 2,752,298 THREADS
    Arch: 4,560 - with 6 MEMBERS online when I looked (inc. me, phrak and cactus) and 105,081 THREADS
    Not sure what that tells us...
    I'd like to stress that this purely a comparison of distro SIZE, not quality, this is nothing to do with what is "best" - just about size and progress

    Well, mark shuttleworth was also a mainline debian developer for quite a while..and was even considered as a potential candidate for the DPL position at one point (he dicided not to run).
    He sold his start up security company, and made his fortune. He decided to 'give back' to the community that helped him get his $$, and to be generally philanthropic. So he started a debain polisher distro, and setup a foundation for it, and hired some smarties.
    that is my understanding from what I have read and heard. He seems like a pretty nice chap from the interviews and writings of his that i have seen. Never met the guy though.

  • Security breach - Unauthorized Account Openning

    Here is a security breach situation which I find baffling today 12/20/2014:
    Today 12/20/2014 I'm not accessing the forum nor using any of my browser. Instead I was filling out some form in Word. While printing, my computer printed out the filled form plus an OPEN Lenovo account (mine) responding to a posting dated 12/15/2014.
    Can anyone make suggestions on what to do with this?
    Solved!
    Go to Solution.

    No worries. Actually I had something happen today that I had not even considered before. I have at a minimum 4 different laptops connected wirelessly to a router that has a wired connection to our printer. All 4 of the laptops in the house were using the 2.5MHz radio (dual band router) and I have been having a horrendous problem of my personal main laptop dropping its wireless connection. Tonight I decided to do something about it. After many hours of frustrating trial and error I did something that I had not even considered before. I have one laptop that also has a dual band wireless radio, so I switched it to use the 5MHz radio. All of the sudden my problems were solved, but I heard my printer running. Went to check it and it looked like the print spooler had puked. Just 3 lines of random characters Nothing anyone had tried printing ever. No one had even tried printing anything at all today, and there was nothing in the printer spool or in the cache.
    Now I do not know if this has anything to do with what you are seeing, but it is strange. Have you been having network problems of any kind? I am just praying my network issues are over. I have been online for just over 2 hrs straight and not a single knockoff.
    Hoov
    Microsoft MVP - Consumer Security
    SpywareHammer.com

  • Want to leave CC after security breach. No support.

    After Adobe's security breach, my card was cancelled by my bank the week I was to stand in a wedding.
    I've tried to contact support in four different ways and finally recieved a call-back last week. They told me they would credit me through January, and would contact me later after "escelating my claim."
    That night, I got a voicemail saying they were still looking into my claim and today, on deadline, I can't open any of my programs. I call them "my programs" because I've already paid over $300 for them. It only seems fair.
    Having spent a year (and $360) licensing software and having absolutely no support, I want a download key for the three programs I use. I want to be done with CC and Adobe at large while still being able to do my work.

    Your message is entitled in part "Want to leave CC".
    I'm not saying that you shouldn't be upset and cynical., but if you are posting here as more of a threatening rant to get some attention, rather than actually request an Adobe employee explicitly cancel your membership, you probably should actually say what you want occur, not the opposite of what you want to occur. 
    For example, despite this being a user-to-user forum, I have seen an Adobe employee Beverly Gray come along and either cancel memberships or re-submit payment transactions for people who request such.
    An Adobe person cannot make CC a non-subscription product if you're asking for an activation key, but if you have a new credit-card number entered into your account and the payments are not going through, then say that, and see if someone will help you.

  • Did you know when you type in your email in google your behance pdf resume shows up? This is a security breach!

    I typed my email address in Google and my Behance pdf resume shows up with all my information. Did you all know this? This is a security breach in my opinion.
    Message was edited by: Carol Smith

    HI Carol,
    Thanks for writing. It looks like you had selected your work experience to be visible to the public, so this is why it was visible online. Now I see that you have your work experience listed as private (other than what you have on your profile), so this should no longer be the case. Let me know if you're still seeing this searh result and what exact google term you searched for it to come up.
    Thanks, talk to you soon!

Maybe you are looking for

  • Connect not recording sound at various times or displaying certain visual in Photoshop

    Hello, Has anyone had a problem with Connect not recording sound in various places or not showing visuals like the marching ants in Photoshop or the red overlay when resizing the cursor which is also in Photoshop? Stephen Burns

  • I have the exact same issue

    I am having the exact same issue.  Only difference is I am using 2 RV180's.  Same firmware version and same symptoms.  My setup crashes every 2-3.5 days and I can NEVER get it to re-establish using the GUI, I always have to re-boot one side or the ot

  • ORDERS02 -- E1EDP04 and 05 segments notgetting generated

    Hi, In ECC 6.0 when we are creating PO using transaction me21n we are using output type which is having a medium of EDI. After creating PO ORDERS.ORDERS02 idoc gets generated. Now when we populate Tax and Pricing informations then the Tax and Pricing

  • Your favorite resources about effective learning in Captivate?

    Hi, I'm just getting started with Captivate, though I've been working in instructional design in digital publishing for education for a while. Now I'm going for my master's, and I'm planning on doing some hands-on action research about effective ways

  • Anyone using reason 4.0 with logic?

    im using reason 4.0 abby road samples and im getting latency when i try to record tracks. i have a 2.0 processor and 2 gigs of ram. any advice?