Webmin mirror served backdoor
A compromised SourceForge mirror distributed a modified Webmin 1.290 archive.
Story
In August 2006, a Webmin 1.290 archive served from a SourceForge mirror was reported as modified. The compromise was distribution-side. Users following a normal download path could receive a tarball that did not match the expected project release.
The record is intentionally narrow. It tracks the affected archive, the mirror path, and the known hashes for the malicious file. It does not treat the ordinary Webmin 1.290 vulnerability history as the same event, because a vulnerable release and a replaced distribution artifact are different failures.
The operational risk came from where Webmin runs. Webmin is an administrative interface for Unix and Linux systems, commonly exposed on management ports and often used with high privilege. A modified archive in that path can become code execution in the management plane.
The durable lesson is provenance. SourceForge was a trusted distribution surface, but the mirror copy still had to be verified. The archive name and version were not enough; hashes separated the served artifact from the intended release.
Affected Artifacts
webmin
- Observed
- 2006-08-10 to 2006-08-13
- Compromised Versions
-
- 1.290
- Fixed
- Not listed
- Hashes
-
- md5:4586a745fe837e1b21a1d2f56bb5a81d
- sha1:aa60916d5632e4adaac5b0fa01fb6a9b35f15cd6
Incident Context
- Motive
- Unauthorized Access Control
- Attribution
- Person
- Cause
- Compromised Infrastructure
- Transitive
- No
- Actor
- Individual Hacker
External References
- Webmin: Securitywebmin.com
- The hole tricktheregister.com
- SANS ISC: Webmin 1.290 Backdoorisc.sans.edu
Source record: oss/attacks/webmin/2006/meta.yaml