Settings

Theme

OpenWRT Docs "have reason to suspect a security compromise"

openwrt.org

9 points by octoluke 2 years ago · 3 comments

Reader

outsidein 2 years ago

jow SysAdmin 8m Update:

After reviewing the situation we found no indication of any unauthorized access to the system.

Background:

During maintenance work to implement performance improvements for the table of hardware (ToH) views on the wiki, which are currently the primary reason for severe system load, we encountered a debug log containing username and passwords of login attempts in clear text.

What we initially believed to be a malicious modification of the DokuWiki PHP code turned out to be leftover debug code from an earlier wiki migration. We removed the offending debug functionality and purged the related log file. As a precaution, we're going to force a password reset for all users.

Note that the user database itself contains one-way password hashes and was not compromised, neither did we find an indication of any unauthorized access.

ratsmack 2 years ago

It seems to me that excursions into various websites has increased this past year. Every day or so someone else reveals that they have been compromised, and these are usually only higher profile sites. One has to wonder what might be the total number of sites that are compromised on any given day.

greyface- 2 years ago

Returns 404 now, and whatever was there was wasn't captured by web.archive.org or archive.today.

Keyboard Shortcuts

j
Next item
k
Previous item
o / Enter
Open selected item
?
Show this help
Esc
Close modal / clear selection