{"id":2994,"date":"2016-02-21T01:44:13","date_gmt":"2016-02-21T01:44:13","guid":{"rendered":"http:\/\/blog.linuxmint.com\/?p=2994"},"modified":"2016-02-21T03:48:24","modified_gmt":"2016-02-21T03:48:24","slug":"beware-of-hacked-iso-if-you-downloaded-linux-mint-on-february-20th","status":"publish","type":"post","link":"https:\/\/blog.linuxmint.com\/?p=2994","title":{"rendered":"Beware of hacked ISOs if you downloaded Linux Mint on February 20th!"},"content":{"rendered":"<p>I&#8217;m sorry I have to come with bad news.<\/p>\n<p>We were exposed to an intrusion today. It was brief and it shouldn&#8217;t impact many people, but if it impacts you, it&#8217;s very important you read the information below.<\/p>\n<p><strong>What happened?<\/strong><\/p>\n<p>Hackers made a modified Linux Mint ISO, with a backdoor in it, and managed to hack our website to point to it.<\/p>\n<p><strong>Does this affect you?<\/strong><\/p>\n<p>As far as we know, the only compromised edition was Linux Mint 17.3 Cinnamon edition.<\/p>\n<p>If you downloaded another release or another edition, this does not affect you. If you downloaded via torrents or via a direct HTTP link, this doesn&#8217;t affect you either.<\/p>\n<p>Finally, the situation happened today, so it should only impact people who downloaded this edition on February 20th.<\/p>\n<p><strong>How to check if your ISO is compromised?<\/strong><\/p>\n<p>If you still have the ISO file, check its MD5 signature with the command &#8220;md5sum yourfile.iso&#8221; (where yourfile.iso is the name of the ISO).<\/p>\n<p>The valid signatures are below:<\/p>\n<pre>6e7f7e03500747c6c3bfece2c9c8394f  linuxmint-17.3-cinnamon-32bit.iso\r\ne71a2aad8b58605e906dbea444dc4983  linuxmint-17.3-cinnamon-64bit.iso\r\n30fef1aa1134c5f3778c77c4417f7238  linuxmint-17.3-cinnamon-nocodecs-32bit.iso\r\n3406350a87c201cdca0927b1bc7c2ccd  linuxmint-17.3-cinnamon-nocodecs-64bit.iso\r\ndf38af96e99726bb0a1ef3e5cd47563d  linuxmint-17.3-cinnamon-oem-64bit.iso\r\n<\/pre>\n<p>If you still have the burnt DVD or USB stick, boot a computer or a virtual machine offline (turn off your router if in doubt) with it and let it load the live session.<\/p>\n<p>Once in the live session, if there is a file in \/var\/lib\/man.cy, then this is an infected ISO.<\/p>\n<p><strong>What to do if you are affected?<\/strong><\/p>\n<p>Delete the ISO. If you burnt it to DVD, trash the disc. If you burnt it to USB, format the stick.<\/p>\n<p>If you installed this ISO on a computer:<\/p>\n<ul>\n<li>Put the computer offline.<\/li>\n<li>Backup your personal data, if any.<\/li>\n<li>Reinstall the OS or format the partition.<\/li>\n<li>Change your passwords for sensitive websites (for your email in particular).<\/li>\n<\/ul>\n<p><strong>Is everything back to normal now?<\/strong><\/p>\n<p>Not yet. We took the server down while we&#8217;re fixing the issue.<\/p>\n<p><strong>Who did that?<\/strong><\/p>\n<p>The hacked ISOs are hosted on 5.104.175.212 and the backdoor connects to absentvodka.com.<\/p>\n<p>Both lead to Sofia, Bulgaria, and the name of 3 people over there. We don&#8217;t know their roles in this, but if we ask for an investigation, this is where it will start.<\/p>\n<p>What we don&#8217;t know is the motivation behind this attack. If more efforts are made to attack our project and if the goal is to hurt us, we&#8217;ll get in touch with authorities and security firms to confront the people behind this.<\/p>\n<p>If you&#8217;ve been affected by this, please do let us know.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>I&#8217;m sorry I have to come with bad news. We were exposed to an intrusion today. It was brief and it shouldn&#8217;t impact many people, but if it impacts you, it&#8217;s very important you read the information below. What happened? Hackers made a modified Linux Mint ISO, with a backdoor in it, and managed to [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[],"class_list":["post-2994","post","type-post","status-publish","format-standard","hentry","category-main-topics"],"_links":{"self":[{"href":"https:\/\/blog.linuxmint.com\/index.php?rest_route=\/wp\/v2\/posts\/2994","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/blog.linuxmint.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blog.linuxmint.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blog.linuxmint.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/blog.linuxmint.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=2994"}],"version-history":[{"count":5,"href":"https:\/\/blog.linuxmint.com\/index.php?rest_route=\/wp\/v2\/posts\/2994\/revisions"}],"predecessor-version":[{"id":2999,"href":"https:\/\/blog.linuxmint.com\/index.php?rest_route=\/wp\/v2\/posts\/2994\/revisions\/2999"}],"wp:attachment":[{"href":"https:\/\/blog.linuxmint.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=2994"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blog.linuxmint.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=2994"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blog.linuxmint.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=2994"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}