J.E.B.
Dear all,
We just enabled all mail services for linuxaudio.org again. All mailing
lists are working again and mail can be sent and received for the
linuxaudio.org domain.
A short recap of what happened is that linuxaudio.org got compromised on
January 29th, probably with a compromised private SSH key or password
from an account with shell access. The attacker checked the kernel, saw
that it was vulnerable to Dirty COW¹, pulled in an exploit and got root.
This was quickly discovered by the IT department of Virginia Tech
University that disconnected the server from the internet and started a
forensic investigation procedure. As part of their IT security policy
the server had to be reinstalled and everything had to be set up from
scratch again. In the meanwhile I built an alternative setup and after
some discussion we agreed on moving linuxaudio.org away from the
Virginia Tech server.