<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" 
     xmlns:content="http://purl.org/rss/1.0/modules/content/"
     xmlns:wfw="http://wellformedweb.org/CommentAPI/"
     xmlns:dc="http://purl.org/dc/elements/1.1/"
     xmlns:meneame="http://meneame.net/faq-es.php"
 >
<channel>
	<title>Menéame: comentarios [927738]</title>
	<link>http://www.meneame.net</link>
	<image><title>www.meneame.net</title><link>http://www.meneame.net</link><url>http://cdn.mnmstatic.net/img/mnm/eli-rss.png</url></image>
	<description>Sitio colaborativo de publicación y comunicación entre blogs</description>
	<pubDate>Wed, 14 Apr 2010 05:37:11 +0000</pubDate>
	<generator>http://blog.meneame.net/</generator>
	<language>es</language>
	<item>
		<meneame:comment_id>6090789</meneame:comment_id>
		<meneame:link_id>927738</meneame:link_id>
		<meneame:order>3</meneame:order>
		<meneame:user>cbr600f</meneame:user>
		<meneame:votes>0</meneame:votes>
		<meneame:karma>7</meneame:karma>
		<meneame:url>https://www.meneame.net/story/servidor-jira-apache-hackeado-instan-cambiar-passwords-eng</meneame:url>
		<title>#3 Servidor Jira de Apache hackeado, Instan cambiar passwords [ENG]</title>
		<link>https://www.meneame.net/story/servidor-jira-apache-hackeado-instan-cambiar-passwords-eng/c03#c-3</link>
		<pubDate>Wed, 14 Apr 2010 05:37:11 +0000</pubDate>
		<dc:creator>cbr600f</dc:creator>
		<guid>https://www.meneame.net/story/servidor-jira-apache-hackeado-instan-cambiar-passwords-eng/c03#c-3</guid>
		<description><![CDATA[<p><a class="tooltip c:927738-2" href="https://www.meneame.net/story/servidor-jira-apache-hackeado-instan-cambiar-passwords-eng/c02#c-2" rel="nofollow">#2</a> más bien al revés no?</p><p>&#187;&nbsp;autor: <strong>cbr600f</strong></p>]]></description>
	</item>

	<item>
		<meneame:comment_id>6089996</meneame:comment_id>
		<meneame:link_id>927738</meneame:link_id>
		<meneame:order>2</meneame:order>
		<meneame:user>--1--</meneame:user>
		<meneame:votes>0</meneame:votes>
		<meneame:karma>13</meneame:karma>
		<meneame:url>https://www.meneame.net/story/servidor-jira-apache-hackeado-instan-cambiar-passwords-eng</meneame:url>
		<title>#2 Servidor Jira de Apache hackeado, Instan cambiar passwords [ENG]</title>
		<link>https://www.meneame.net/story/servidor-jira-apache-hackeado-instan-cambiar-passwords-eng/c02#c-2</link>
		<pubDate>Tue, 13 Apr 2010 21:14:57 +0000</pubDate>
		<dc:creator>--1--</dc:creator>
		<guid>https://www.meneame.net/story/servidor-jira-apache-hackeado-instan-cambiar-passwords-eng/c02#c-2</guid>
		<description><![CDATA[<p>dupe: <a href="http://www.meneame.net/story/fundacion-apache-atacada-han-robado-contrasenas-todos-usuarios" title="www.meneame.net/story/fundacion-apache-atacada-han-robado-contrasenas-todos-usuarios" rel="nofollow">www.meneame.net/story/fundacion-apache-atacada-han-robado-contrasenas-</a></p><p>&#187;&nbsp;autor: <strong>--1--</strong></p>]]></description>
	</item>

	<item>
		<meneame:comment_id>6088659</meneame:comment_id>
		<meneame:link_id>927738</meneame:link_id>
		<meneame:order>1</meneame:order>
		<meneame:user>cbr600f</meneame:user>
		<meneame:votes>0</meneame:votes>
		<meneame:karma>7</meneame:karma>
		<meneame:url>https://www.meneame.net/story/servidor-jira-apache-hackeado-instan-cambiar-passwords-eng</meneame:url>
		<title>#1 Servidor Jira de Apache hackeado, Instan cambiar passwords [ENG]</title>
		<link>https://www.meneame.net/story/servidor-jira-apache-hackeado-instan-cambiar-passwords-eng/c01#c-1</link>
		<pubDate>Tue, 13 Apr 2010 16:57:42 +0000</pubDate>
		<dc:creator>cbr600f</dc:creator>
		<guid>https://www.meneame.net/story/servidor-jira-apache-hackeado-instan-cambiar-passwords-eng/c01#c-1</guid>
		<description><![CDATA[<p>Más información:<br />
<br />
<a href="http://people.apache.org/~joes/jira-hacked.txt" title="people.apache.org/~joes/jira-hacked.txt" rel="nofollow">people.apache.org/~joes/jira-hacked.txt</a><br />
<br />
<a href="http://moojix.wordpress.com/2010/04/13/jira-at-apache-org-was-hacked/" title="moojix.wordpress.com/2010/04/13/jira-at-apache-org-was-hacked/" rel="nofollow">moojix.wordpress.com/2010/04/13/jira-at-apache-org-was-hacked/</a><br />
<br />
Este es el email envíado a los usuarios registrados<br />
<br />
&#34;Dear XXXXXX,<br />
<br />
You are receiving this email because you have a login, 'xxxxxx', on the Apache JIRA installation, <a href="https://issues.apache.org/jira/" title="issues.apache.org/jira/" rel="nofollow">issues.apache.org/jira/</a><br />
<br />
On April 6 the issues.apache.org server was hacked. The attackers were able to install a trojan JIRA login screen and later get full root access:<br />
<br />
<a href="https://blogs.apache.org/infra/entry/apache_org_04_09_2010" title="blogs.apache.org/infra/entry/apache_org_04_09_2010" rel="nofollow">blogs.apache.org/infra/entry/apache_org_04_09_2010</a><br />
<br />
We are assuming that the attackers have a copy of the JIRA database, which includes a hash (SHA-512 unsalted) of the password<br />
you set when signing up as 'xxxxxxx' to JIRA. If the password you set was not of great quality (eg. based on a dictionary word), it<br />
should be assumed that the attackers can guess your password from the password hash via brute force.<br />
<br />
The upshot is that someone malicious may know both your email address and a password of yours.<br />
<br />
This is a problem because many people reuse passwords across online services. If you reuse passwords across systems, we urge you to change<br />
your passwords on ALL SYSTEMS that might be using the compromised JIRA password. Prime examples might be gmail or hotmail accounts, online<br />
banking sites, or sites known to be related to your email's domain, gmail.com.<br />
<br />
Naturally we would also like you to reset your JIRA password. That can be done at:<br />
<br />
<a href="https://issues.apache.org/jira/secure/ForgotPassword!default.jspa?username=xxxxxxx" title="issues.apache.org/jira/secure/ForgotPassword!default.jspa?username=xxxxxxx" rel="nofollow">issues.apache.org/jira/secure/ForgotPassword!default.jspa?username=xxx</a><br />
<br />
We (the Apache JIRA administrators) sincerely apologize for this security breach. If you have any questions, please let us know by email.<br />
We are also available on the <a href="/search?w=comments&#38;q=%23asfinfra&#38;o=date">#asfinfra</a> IRC channel on irc.freenode.net.<br />
<br />
Regards,<br />
<br />
The Apache Infrastructure Team&#34;</p><p>&#187;&nbsp;autor: <strong>cbr600f</strong></p>]]></description>
	</item>

</channel>
</rss>
