A built-in password for accessing the user database has been discovered in the Linuxfx distribution.

Members of the Kernal community have identified an unusually careless attitude toward security in the Linuxfx distribution, which offers an Ubuntu build with a KDE user environment styled like the Windows 11 interface. According to data from the project's website, the distribution is used by over a million users, with approximately 15,000 downloads recorded this week. The distribution offers additional paid features that are activated by entering a license key in a special graphical application.

An investigation into the license activation application (/usr/bin/windowsfx-register) revealed that it includes a hard-coded login and password for accessing an external MySQL database, into which new user data is added. The credentials used allow full access to the database, including the 'machines' table, which reflects information about all installations of the distribution, including an IP address users. The contents of the 'fxkeys' table, which holds license keys and email addresses of all registered commercial users, are also accessible. Notably, despite claims of a million users, the database contains only 20,000 records. The application is written in Visual Basic and runs using the Gambas interpreter.

The reaction of the developers of the distribution deserves special attention. Following the publication of information about the security issues, they released an update that did not fix the problem itself, but merely changed the database name, login, and password, as well as altered the logic of obtaining credentials and attempted to combat program tracing. Instead of hard-coded credentials in the application, the Linuxfx developers added the ability to load database connection parameters externally server, using the curl utility. For protection after launch, a search and removal of all running 'sudo', 'stapbp', and '*-bpfcc' processes in the system has been implemented, apparently believing that this would prevent tracing programs from functioning.

A built-in password for accessing the user database has been discovered in the Linuxfx distribution.


Source: opennet.ru
Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster