Symbianize Forum

Most of our features and services are available only to members, so we encourage you to login or register a new account. Registration is free, fast and simple. You only need to provide a valid email. Being a member you'll gain access to all member forums and features, post a message to ask question or provide answer, and share or find resources related to mobile phones, tablets, computers, game consoles, and multimedia.

All that and more, so what are you waiting for, click the register button and join us now! Ito ang website na ginawa ng pinoy para sa pinoy!

[WARNING!] Linux Mint Os Downloaded On Feb 20 2016

OperatingSystem

Novice
Diamond Member
Messages
32
Reaction score
1
Points
428
Perfect Health
Eternal Love
Royal Wisdom
Solid Family
Ultimate Endurance
Endless Happiness
Mind Stone
Space Stone
Good Luck
Enormous Fortune
Divine Faith
Absolute Peace
KUNG IKAW AY NAG DOWNLOAD OR INSTALL NANG LINUX MINT 17.3 CINNAMON ROSA NUNG FEBRUARY 20, 2016 PAKI REMOVE OR REINSTALL NA AGAD ANG LINUX MINT OS NA NILAGAY MO LAPTOP OR PC MO DAHIL ITO AY MAY BACKDOOR NAILAGAY NANG MGA HACKER ANG MODIFIED VERSION NANG LINUX MINT SA MAIN WEBSITE AT PINALITAN ANG OFFICIAL ISO NANG LINUX MINT SA MAIN WEBSITE . TO READ MORE ABOUT THIS ISSUE YOU CAN READ THIS AND SEE THE REFERENCES BELOW

Beware of hacked ISOs if you downloaded Linux Mint on February 20th!

I’m sorry I have to come with bad news.

We were exposed to an intrusion today. It was brief and it shouldn’t impact many people, but if it impacts you, it’s very important you read the information below.

What happened?

Hackers made a modified Linux Mint ISO, with a backdoor in it, and managed to hack our website to point to it.

Does this affect you?

As far as we know, the only compromised edition was Linux Mint 17.3 Cinnamon edition.

If you downloaded another release or another edition, this does not affect you. If you downloaded via torrents or via a direct HTTP link, this doesn’t affect you either.

Finally, the situation happened today, so it should only impact people who downloaded this edition on February 20th.

How to check if your ISO is compromised?

If you still have the ISO file, check its MD5 signature with the command “md5sum yourfile.iso” (where yourfile.iso is the name of the ISO).

The valid signatures are below:

6e7f7e03500747c6c3bfece2c9c8394f linuxmint-17.3-cinnamon-32bit.iso
e71a2aad8b58605e906dbea444dc4983 linuxmint-17.3-cinnamon-64bit.iso
30fef1aa1134c5f3778c77c4417f7238 linuxmint-17.3-cinnamon-nocodecs-32bit.iso
3406350a87c201cdca0927b1bc7c2ccd linuxmint-17.3-cinnamon-nocodecs-64bit.iso
df38af96e99726bb0a1ef3e5cd47563d linuxmint-17.3-cinnamon-oem-64bit.iso


If you still have the burnt DVD or USB stick, boot a computer or a virtual machine offline (turn off your router if in doubt) with it and let it load the live session.

Once in the live session, if there is a file in /var/lib/man.cy, then this is an infected ISO.

What to do if you are affected?

Delete the ISO. If you burnt it to DVD, trash the disc. If you burnt it to USB, format the stick.

If you installed this ISO on a computer:

Put the computer offline.
Backup your personal data, if any.
Reinstall the OS or format the partition.
Change your passwords for sensitive websites (for your email in particular).
Is everything back to normal now?

Not yet. We took the server down while we’re fixing the issue.

Who did that?

The hacked ISOs are hosted on 5.104.175.212 and the backdoor connects to absentvodka.com.

Both lead to Sofia, Bulgaria, and the name of 3 people over there. We don’t know their roles in this, but if we ask for an investigation, this is where it will start.

What we don’t know is the motivation behind this attack. If more efforts are made to attack our project and if the goal is to hurt us, we’ll get in touch with authorities and security firms to confront the people behind this.

If you’ve been affected by this, please do let us know.

REFERENCE : http://blog.linuxmint.com/?p=2994
http://www.theregister.co.uk/2016/0...lwareinfected_isos_linked_from_official_site/
http://thehackernews.com/2016/02/linux-mint-hack.html
 
Last edited:
Thanks po dito sir.
Napanood ko po ito sa Threatwire. :thanks:
 
Thanks po dito sir.
Napanood ko po ito sa Threatwire. :thanks:

Actually late nako nakapag REPOST nang news kasi mejo busy pero ako mismo nag install ako nung saturday kaya dalidali ko kaagad inalis yung Newly installed ko na linuxmint nung nabasa ko to
 
Actually late nako nakapag REPOST nang news kasi mejo busy pero ako mismo nag install ako nung saturday kaya dalidali ko kaagad inalis yung Newly installed ko na linuxmint nung nabasa ko to

Ah...kaya pala. :) buti na lang po nabasa nyo.
Change password po kayo sa mga accounts nyo sir: fb, twitter, bank, etc. lahat po nung nalogin mong accounts sa Mint. Hopefully walang nangyari sa mga accounts niyo. :)
 
Mukhang Alarming nga ito,sana sa ESKWELA OS natin eh Malinis ^_^

I assure you po na wala pong ganyan sa Eskwela OS. :)
because:
1. the iso is uploaded to sourceforge.
Sourceforge has good security for all opensource software. I am very confident with their security.
2. Ako pa lang po ang developer nito. Wala pa codeveloper, thus, from building to packaging wala pong mga malicious scripts na ginawa.

sa linux mint kasi, maraming developers po kaya ang bilis ng development ng Linux. Eh sa Eskwela, ako pa lang po tapos, hindi ako always naka-internet, kasi hirap mgconnect noon. :D always delayed ang release. :lol:
 
I assure you po na wala pong ganyan sa Eskwela OS. :)
because:
1. the iso is uploaded to sourceforge.
Sourceforge has good security for all opensource software. I am very confident with their security.
2. Ako pa lang po ang developer nito. Wala pa codeveloper, thus, from building to packaging wala pong mga malicious scripts na ginawa.

sa linux mint kasi, maraming developers po kaya ang bilis ng development ng Linux. Eh sa Eskwela, ako pa lang po tapos, hindi ako always naka-internet, kasi hirap mgconnect noon. :D always delayed ang release. :lol:

actually di naman ako nag log in dun dual boot kasi ako nag practice lang ako for some hacking stuffs kaya nag try ako mag linux mint pero secure na lahat accounts ko :)
 
salamat sa info buti na lang pala pagka release ng rosa na update ko na agad
 
lupit ng hacker , plan ko pa naman mag dl ng linux mint
 
Ubuntu based din ang Linux Mint diba? pero meron din Debian based. Issue ko sa mga Ubuntu based ay di sure kung 100% free software at no backdoors dahil sa issue sa Ubuntu: Amazon data leak etc.:
https://github.com/nylira/prism-break/issues/334
https://www.gnu.org/philosophy/ubuntu-spyware.html

Sourceforge naman puro ads at naireport na pinalitan yung downloadable exe with ad-added exe kaya dapat meron tayong GPG at Hash verification. Mas safe na rin yung GPG kesa Hash dahil malalaman kung tampered yung file na dinownload naten.

Debian user here.
 
Back
Top Bottom