{"id":3275,"date":"2017-04-05T15:16:13","date_gmt":"2017-04-05T15:16:13","guid":{"rendered":"http:\/\/blog.mageia.org\/en\/?p=3275"},"modified":"2017-05-26T21:00:30","modified_gmt":"2017-05-26T21:00:30","slug":"web-services-shut-down-preventively","status":"publish","type":"post","link":"https:\/\/blog.mageia.org\/en\/2017\/04\/05\/web-services-shut-down-preventively\/","title":{"rendered":"Web services shut down preventively"},"content":{"rendered":"<p>Our sysadmins decided to preventively shut down most of our web services which were still running on end-of-life\u00a0Mageia versions, as their potential vulnerability to remote attacks was publicised\u00a0in third party communities.<\/p>\n<p>The migration of those services to Mageia 5 servers was planned but delayed due to a lack of sysadmin time to work on it. The unexpected publicity that it received\u00a0obviously made this topic a high priority one, our infrastructure being exposed as an easy target. The sysadmins therefore decided to shut down the services to be able to work on the migration without further risks.<\/p>\n<p>Please note that our buildsystems for packages and ISO images\u00a0are running the latest stable release, and therefore Mageia users need (as far as we know at this stage) not be concerned. The potential risks should be confined to web services of the mageia.org domain \u2013 we are nevertheless auditing all servers for traces of intrusion which could have been facilitated by the outdated infrastructure.<\/p>\n<p>We are sorry for the disagreement and this security negligence, and will keep you posted with our progress on this issue and the verification of the services.<\/p>\n<p>Current status:<\/p>\n<ul>\n<li>Homepage (www): <strong><span style=\"color: #00c400;\">online<\/span><\/strong><\/li>\n<li>Blog: <strong><span style=\"color: #00c400;\">online<\/span><\/strong><\/li>\n<li>Identity:\u00a0<strong><span style=\"color: #00c400;\">online<\/span><\/strong><\/li>\n<li>Bugzilla (bugs):\u00a0<strong><span style=\"color: #00c400;\">online<\/span><\/strong><\/li>\n<li>Mailing list (ml):\u00a0<strong><span style=\"color: #00c400;\">online<\/span><\/strong><\/li>\n<li>Wiki: <span style=\"color: #000000;\"><strong><span style=\"color: #00c400;\">online<\/span><\/strong><\/span><\/li>\n<li>Forums:\u00a0<span style=\"color: #000000;\"><strong><span style=\"color: #00c400;\">online<\/span><\/strong><\/span><\/li>\n<li>Mirrors index and MIRRORLIST (mirrors):<b>\u00a0<strong><span style=\"color: #00c400;\">online<\/span><\/strong><\/b><span style=\"color: #ff0000;\"><br \/>\n<\/span><\/li>\n<li>Git \/ Svn: <strong><span style=\"color: #00c400;\">online<\/span><\/strong><\/li>\n<li>Gitweb \/ Svnweb:\u00a0<strong><span style=\"color: #00c400;\">online<\/span><\/strong><\/li>\n<li>Buildsystem (pkgsubmit): <strong><span style=\"color: #00c400;\">online<\/span><\/strong><\/li>\n<li>Mageia App DB (madb): <strong><span style=\"color: #00c400;\">online<\/span><\/strong><\/li>\n<\/ul>\n<hr \/>\n<p><em>Edit Apr 5, 2017 @ 17:45:<\/em> Added more details about services being down and the security risks.<\/p>\n<p><em>Edit Apr 5, 2017 @ 20:45: <\/em>Instructions to add a specific mirror manually for MIRRORLIST users.<\/p>\n<p><em>Edit Apr 6, 2017 @ 8:00:<\/em> Web services had been\u00a0mistakenly put back online automatically during the night, they are now back offline as necessary.<\/p>\n<p><em>Edit Apr 8, 2017 @ 1:00:<\/em> Bugzilla and MIRRORLIST are functional again. Bugzilla was also updated to the latest 5.0.3+ upstream version.<\/p>\n<p><em>Edit Apr 9, 2017 @ 0:15:<\/em> Identity is back online.<\/p>\n<p><em>Edit Apr 20, 2017 @ 15:00:<\/em> Wiki is back online. Gitweb and Svnweb were also restored in the past week, and the mailing list software will be back soon.<\/p>\n<p><em>Edit May 26, 2017 @ 21:00:<\/em> As of now all services are back online! Thanks to our sysadmins for their precious time! \ud83d\ude42<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Our sysadmins decided to preventively shut down most of our web services which were still running on end-of-life\u00a0Mageia versions, as their potential vulnerability to remote attacks was publicised\u00a0in third party communities. The migration of those services to Mageia 5 servers &hellip; <a href=\"https:\/\/blog.mageia.org\/en\/2017\/04\/05\/web-services-shut-down-preventively\/\">Continue reading <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":20,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"jetpack_post_was_ever_published":false,"_jetpack_newsletter_access":"","_jetpack_dont_email_post_to_subs":false,"_jetpack_newsletter_tier_id":0,"_jetpack_memberships_contains_paywalled_content":false,"_jetpack_memberships_contains_paid_content":false,"footnotes":"","jetpack_publicize_message":"","jetpack_publicize_feature_enabled":true,"jetpack_social_post_already_shared":true,"jetpack_social_options":{"image_generator_settings":{"template":"highway","enabled":false},"version":2}},"categories":[124,159,11],"tags":[],"class_list":["post-3275","post","type-post","status-publish","format-standard","hentry","category-mageia-2","category-security","category-sysadmin"],"jetpack_publicize_connections":[],"jetpack_featured_media_url":"","jetpack_shortlink":"https:\/\/wp.me\/p159kA-QP","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/blog.mageia.org\/en\/wp-json\/wp\/v2\/posts\/3275","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/blog.mageia.org\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blog.mageia.org\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blog.mageia.org\/en\/wp-json\/wp\/v2\/users\/20"}],"replies":[{"embeddable":true,"href":"https:\/\/blog.mageia.org\/en\/wp-json\/wp\/v2\/comments?post=3275"}],"version-history":[{"count":36,"href":"https:\/\/blog.mageia.org\/en\/wp-json\/wp\/v2\/posts\/3275\/revisions"}],"predecessor-version":[{"id":3431,"href":"https:\/\/blog.mageia.org\/en\/wp-json\/wp\/v2\/posts\/3275\/revisions\/3431"}],"wp:attachment":[{"href":"https:\/\/blog.mageia.org\/en\/wp-json\/wp\/v2\/media?parent=3275"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blog.mageia.org\/en\/wp-json\/wp\/v2\/categories?post=3275"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blog.mageia.org\/en\/wp-json\/wp\/v2\/tags?post=3275"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}