Thread-topic: Debian development server compromised
http://isc.sans.org/diary.php?storyid=1479
Debian development server compromised
Published: 2006-07-12,
Last Updated: 2006-07-12 23:04:09 UTC by Jason Lam (Version: 1)
Looks like the debian developement server (hosting the cvs amongst other
services) has been compromised. The Debian folks are still investigating
the incidents at this point. No words on whether the any source code
were altered yet.
>From stories like these, we can't stress the point of having a HIDS
system. From experience, some server could be compromised over 6 months
before someone even notice about it. Having some type of HIDS such as
AIDE or Tripwire can hopefully reduce the detection time.