We’ve been hit again by this: http://www.linuxmint.com/blog/?p=235

The good news this time is that we’ll be faster to get rid of it (we’ve got really up to date backups), the bad news is that we’re still obviously vulnerable despite the measures we took the last time. I’ll ask Michael (our sysadmin) to look into this and to find out how this could have happened.

I’ll keep you posted.. I just found out about it a few minutes ago.

Update #1: A backdoor virus was found so it’s possible we got re-infected from the inside. I’m currently re-applying updates to clean the website first.

Update #2: The Wiki, forums, blog, software portal and main website are now clean.

Update #3: I’ll be upgrading the forums to the latest version of phpBb today so they might be offline or disabled for a while.

Update #4: The forums were upgraded to the latest version of phpBB. We’re missing the global announcements and there’s a little problem with the theme but overall they’re back online and they should be working fine.

Update #5: The blog was upgraded to the latest version of WordPress.

Update #6: The wiki was upgraded to the latest version of MediaWiki. We also know more about the problem now.. the first attack left a virus called PHP.RSTBackdoor.

Update #7: The planet was upgraded to the latest version of Gregarius.

Update #8: All the cleanup is done. All our tools were upgraded to their latest versions and we made new backups. Michael identified malware uploaded via mintUpload. We’re discussing the possibility to restrict, secure or even discontinue the free part of this service.

* News about Mint

mintInstall 5 was released in Romeo  (the unstable branch of our repositories)

Clem states in the announcement for mintInstall that the Elyssa KDE CE should be released anytime now.

* News about Linux

Security alert:

Adobe Flash ads launching clipboard hijack attack – this works on Windows, Mac and Linux

Better MSN support in Pidgin

Linux popularity across the globe

The final release of Zenwalk Linux 5.2 “GNOME” edition

MEPIS released of antiX MEPIS 7.5 designed to run on computers with older or limited hardware

At approximately the same time as our server was hacked Red Hat / Fedora experienced a more severe intrusion

Link for Fedora (this is the message from Fedora published by IDG.se – the best link I found).

This is now resolved but some packages were signed by the intruder

Microsoft to pay Novell $100 mln more for Linux support

openSUSE to Add SELinux Basic Enablement in 11.1

10 Most Beautiful Plasma Themes for KDE 4 Desktop – more beautiful than Mint KDE 🙂 ?  (Mint still don’t use KDE 4)

* News about IT

SecondLife rolls out Mono-powered servers

Thousands of UK file-sharers face legal action

Comcast to “throttle down” “bandwidth hogs”

UK.gov to spend hundreds of millions on “snooping silo”. This is very similar to a controversial  Swedish act.

A rather technical article on security when you log in to your bank, for those who want a deep background. More here – about PCI-DSS

A growing list of name-brand websites are accused of exposing its readers to dangerous ads.

OSU Open Source Lab gets $300,000 from Google

US presidential candidate John McCain is a pirate

As a result of some skilful phishing 1.5m spam emails  was sent from compromised University accounts

Scammers replace credit card readers in Irish stores

Groups urge states to tackle more cybercrime

* Hardware news

IBM and AMD first at 22 nm, challenge Intel’s manufacturing lead

Intel shows off solid-state drive road maps

Security flaw in Nokia cell phones – did they pay to get the information?
* Trivia and other links   

* More about Linux Mint

How to donate

You find the Wallpaper of the Month in the Blog

Home page

Blog  The planet  Wiki   Forum

* Editors comment

As always – if you find something I’ve missed in the newsletter please tell me – you can post a comment here

Enjoy life

Husse

One of the new features planned for the upcoming Linux Mint 6 “Felicia” is the ability to browse the Software Portal (http://www.linuxmint.com/software) and to install applications directly from the desktop. This feature is now ready and we’d like you to give us a hand in testing it.

We extended the scope of mintInstall and we developed a new frontend which downloads all the relevant data from the Software Portal so you can browse applications and install them without having to use the portal at all. We also defined how the portal and the frontend communicate with each others and formalized the data structure in XML. The frontend itself supports multiple portals (we’ll be talking to tuxsoftware.com for instance, hopefully getdeb.net too, and we’ll eventually publish documentation about this) so although you can only use it to browse the Linux Mint Software Portal right now, it’s only a matter of time before others portals become available.

Here’s a screenshot:

MintInstall 5 is available in Romeo. If you don’t have Romeo enabled you can get the debs from here:

Let us know what you think, report any bug you may find and have a lot of fun with this brand new mintInstall.

To translate mintInstall 5 into your own language, use this forum thread:  http://www.linuxmint.com/forum/viewtopic.php?f=43&t=16242

Note: There was a lot I wanted to say about this but I’ll save it for the release notes. KDE CE is coming out soon, I need to work on x64 and there are still major developments I want to get done before Mint 6 (an upgrade tool for instance). To keep it short, MintInstall 5 is one of the new features planned for Mint 6 but it will also become available as an upgrade for Mint 5.  It will stay in Romeo until we’re happy to consider it stable.. so we’re waiting on your feedback 🙂

Changelog:

  • 5.0: Initial release