Stolen SSH keys used for attacks

  • Email a Friend
  • Print Page
By Shaun Nichols
Aug 28, 2008 4:01 PM
Tags: Stolen | SSH | keys | used | for | attacks

Linux keys harvested by hackers.

Security experts are warning of a new series of Linux attacks that use stolen Secure Shell (SSH) keys.

The SSH protocol is used as a system for securely communicating between networked machines. The system was first designed as a replacement for the less-secure Telnet protocol.

The attack is part of a malware rootkit known as Phalanx2. According to an advisory from the US Computer Emergency Response Team (US-CERT,) the rootkit is a derivation of an older piece of malware and stores itself in a directory known as " /etc/khubd.p2/" which can only be accessed through the "cd" command.

Once installed, the malware scours a user's computer for vulnerable SSH keys and then attempts to use the data to carry out attacks on any connected systems.

Researchers note that the attack does not attempt to steal or use stolen keys that require passwords, leaving administrators with a good method for protecting their systems.

"The biggest defence is to have any keys, especially those used to authenticate to remote machines and certainly internet facing ones, require a passphrase to use," advised Sans researcher John Bambenek.

"Check your logs, especially if you use SSH key-based auth, to identify accesses from remote machines that have no business accessing you."

Bambenek also recommends that users fully patch their systems to cover any vulnerabilities which could make the SSH keys easier to obtain.

Copyright © 2009 vnunet.com


 
Comments

Be the first to comment on this article.
Thoughts on this article? Add a comment below.
Comment:
Want to participate in the discussion?
Or log in now to comment
 
 
Top Stories
Basslink lights up with commercial traffic
Calls for second independent cable.
 
Bluetooth "Big Brother" tracks festival-goers
Might have retail and security applications.
 
Huawei considers Australian 4G lab
But dollars depend on demand.
 
Exclusive Data Centre - Sponsored Content by Microsoft

Latest Comments

""The researchers will only track the devices' MAC address -- a number that identifies each ..."
by forcedregsucks Jul 6, 2009 9:34 PM
 
" Erin Kutz wrote: A tiny fraction of those who use the fast-growing social network phenomenon ..."
by Slatts Jul 6, 2009 8:58 AM
 
"I'm thinking there was some robust discussion in the Sawers household when Sir John got home ..."
by Slatts Jul 6, 2009 8:41 AM
 
"Well... that seems disturbing but I just can't seem to put my finger on why. I think it just ..."
by Slatts Jul 6, 2009 8:35 AM
 
"I'm kind of assuming that the water was used in water cooled condensers for the air-conditioning...."
by Slatts Jul 2, 2009 8:54 PM

Polls

What will you do when your iPhone contract comes up for renewal?




   |   View results
Retain my current service provider
  11%
 
Switch to a cheaper plan
  18%
 
Switch to a better network
  17%
 
Switch to whoever offers free tethering
  18%
 
Change handset altogether
  35%
TOTAL VOTES: 207

Vote