Please fill in the field below to receive your profile link.
ADVERTISEMENT
Stolen SSH keys used for attacks
Linux keys harvested by hackers
Shaun Nichols in San Francisco, vnunet.com28 Aug 2008
ADVERTISEMENT
Security experts are warning of a new series of Linux attacks that use stolen
Secure Shell (SSH) keys.
The SSH protocol is used as a system for securely communicating between
networked machines. The system was first designed as a replacement for the
less-secure Telnet protocol.
The attack is part of a malware rootkit known as Phalanx2. According to an
advisory
from the US Computer Emergency Response Team (US-CERT,) the rootkit is a
derivation of an older piece of malware and stores itself in a directory known
as " /etc/khubd.p2/" which can only be accessed through the "cd" command.
Once installed, the malware scours a user's computer for vulnerable SSH keys
and then attempts to use the data to carry out attacks on any connected systems.
Researchers note that the attack does not attempt to steal or use stolen keys
that require passwords, leaving administrators with a good method for protecting
their systems.
"The biggest defence is to have any keys, especially those used to
authenticate to remote machines and certainly internet facing ones, require a
passphrase to use," advised Sans researcher John Bambenek.
"Check your logs, especially if you use SSH key-based auth, to identify
accesses from remote machines that have no business accessing you."
Bambenek also recommends that users fully patch their systems to cover any
vulnerabilities which could make the SSH keys easier to obtain.
Leading Mobile Network vendore is currently seeking a Process consultant for a positions based either in the Middle east or Africa. We are looking for around 10 years experience with at least 5 years business ... more >
Tier 1 Network solutions provider is currently seeking an experienced Telecommunications sales manager to work in their Abu Dhabi office. There is a brilliant benefits package as well as an attractive salary available for the ... more >
Leading network solutions provider in Egypt is currently seeking and experienced Egyptian Network Operation /Supervision Engineer. There are competitive packages and attractive benefits package on offer for the right candidate. You will be responsible to ... more >
A leading network Solutions vendor is currently seeking an Egyptian national to act as a Service Assurance manager out of their Egyptian office. Ideally we are looking for someone with Vendor based experience however other ... more >More job opportunities