Apache.org hit by SSH key compromise
Summary: The open-source Apache Software Foundation pulled its Apache.org Web site offline for about three hours today because of server hack caused by a compromised SSH key.
The open-source Apache Software Foundation pulled its Apache.org Web site offline for about three hours today because of server hack caused by a compromised SSH key.
A brief message posted on the site (see image below) made it clear the compromise was "not due to any software exploits in Apache itself", but was actually caused by a compromised SSH key.
The group did not say which Apache software servers were affected. UPDATE: An initial report from Apache is now available.
* Screenshot via The H Security. More at Threatpost.com.
Kick off your day with ZDNet's daily email newsletter. It's the freshest tech news and opinion, served hot. Get it.

Talkback
SSH Key password
Why allow keys for backup to come inbound??
addition to bjbrock's point (which it sounds like there was not a password)
why would keys used to copy OUT a backup be allowed to come back in?
It certainly could be that their backup provider was compromised in some
way, but using a secure password, and not allowing inbound shell with
that account would have easily stopped this type of attack.
Chet Wisniewski
www.sophos.com
I'm wondering if this is a fallout from the Debian OpenSSH fiasco
more) generated by a Debian system - or by any
derived distros such as Ubuntu - to have very
low entropy and easily guessable.
Even though Apache is on FreeBSD servers their
certificate provider could have been using a
Debian system for SSH generation. It was a
nasty bug which cost a lot of $$$ because
customers had to re-pay to have good keys re-
issued.
It is good to see Apache Software Foundation
being upfront, candid and very transparent
about it. Kudos.
Despite this incident Apache seems to on top of
things and - above all - forthcoming. They
deserve respect. Somehow I don't think Apple,
Microsoft or Google would be as informative as
Apache are.
You give Apache far too much credit
However the scenario you laid out is possible and I agree with that. I just think you should have left out the "dig" at Apple, MS and Google as they would have reacted the exact same way.
Actually...
I'm not discounting
Its still more damaging to them...
their fault. Once again all they have is their rep
and no marketing campaign to improve it. Both
situations would be damaging but if its their
fault then thats one knock against them. If its
their fault and they stall then thats two knocks
against them. Its just easier to tell it.
RE: Apache.org hit by SSH key compromise
ssh over public internet
RE: Apache.org hit by SSH key compromise
Thanks
Storage Containers
http://www.boxtcontainers.com
RE: Apache.org hit by SSH key compromise
Thanks
Storage Containers
http://www.boxtcontainers.com
RE: Apache.org hit by SSH key compromise
<a href="http://www.yuregininsesi.com">seslisohbet</a> <a href="http://www.yuregininsesi.com">seslichat</a>