WineHQ database compromise - One More Linux Project Fail

Posted by masgeeks on Oct 13, 2011 5:30 AM EDT
thehackernews.com
Mail this story
Print this story

Jeremy White, Codeweavers Founder has announced that access to the WineHQ database has been compromised.

Jeremy White, Codeweavers Founder has announced that access to the WineHQ database has been compromised. "On the one hand, we saw no evidence of harm to any database. We saw no evidence of any attempt to change the database (and candidly, using the real appdb or bugzilla is the easy way to change the database). Unfortunately, the attackers were able to download the full login database for both the appdb and bugzilla. This means that they have all of those emails, as well as the passwords. The passwords are stored encrypted, but with enough effort and depending on the quality of the password, they can be cracked." Anybody who has reused a password stored there probably wants to make some changes fairly soon.

Attackers have used phpMyAdmin, an open source database administration tool, to access the WineHQ project's database and harvest users' appdb and bugzilla access credentials. Wine (Wine Is Not an Emulator) is free open source software that allows users to run Windows applications on Linux and Unix by providing its own native replacements for Windows DLLs. Hosted on SourceForge, Wine source code is licensed under the LGPL. The Wine Project is sponsored by CodeWeavers, which also shares its own code updates with the Project.

Full Story

  Nav
» Read more about: Story Type: News Story, Security; Groups: Linux, LXer

« Return to the newswire homepage

Subject Topic Starter Replies Views Last Post
The difference is... JaseP 9 1,534 Oct 15, 2011 5:15 PM

You cannot post until you login.