
Nichtsdestotrotz sollten betroffene User sicherheitshalber doch mal wieder einen Blick in ihren Account werfen, ob das Passwort aktualisiert werden sollte und welche Mailadresse dem Täter beim Angriff in die Hände gefallen ist. Auf folgende Daten konnte der Angreifer Zugriff erlangen:
„The attacker had the ability to inject certain formatted SQL to the Forums database on the Forums database servers. This gave them the ability to read from any table but we believe they only ever read from the ‘user’ table.
They used this access to download portions of the ‘user’ table which contained usernames, email addresses and IPs for 2 million users. No active passwords were accessed; the passwords stored in this table were random strings as the Ubuntu Forums rely on Ubuntu Single Sign On for logins. The attacker did download these random strings (which were hashed and salted).“
Allerdings konnte kein Zugriff auf folgendes Bereiche der Foreninterna festgestellt werden:
„We know the attacker was NOT able to gain access to any Ubuntu code repository or update mechanism.
We know the attacker was NOT able to gain access to valid user passwords.
We believe the attacker was NOT able to escalate past remote SQL read access to the Forums database on the Forums database servers.
We believe the attacker was NOT able to gain remote SQL write access to the Forums database.
We believe the attacker was NOT able to gain shell access on any of the Forums app or database servers.
We believe the attacker did NOT gain any access at all to the Forums front end servers.
We believe the attacker was NOT able to gain any access to any other Canonical or Ubuntu services.“
Es wurden weitergehende Sicherheitsmaßnahmen durchgeführt, um weitere Zugriffe in Zukunft besser zu vereiteln.