Newsletter:

Skip Navigation LinksHome > News > Security > Stolen SSH keys used for attacks

Stolen SSH keys used for attacks

By Shaun Nichols
28 August 2008 04:01PM
Tags: stolen | ssh | keys | used | attacks

Linux keys harvested by hackers.

Security experts are warning of a new series of Linux attacks that use stolen Secure Shell (SSH) keys.

The SSH protocol is used as a system for securely communicating between networked machines. The system was first designed as a replacement for the less-secure Telnet protocol.

The attack is part of a malware rootkit known as Phalanx2. According to an advisory from the US Computer Emergency Response Team (US-CERT,) the rootkit is a derivation of an older piece of malware and stores itself in a directory known as " /etc/khubd.p2/" which can only be accessed through the "cd" command.

Once installed, the malware scours a user's computer for vulnerable SSH keys and then attempts to use the data to carry out attacks on any connected systems.

Researchers note that the attack does not attempt to steal or use stolen keys that require passwords, leaving administrators with a good method for protecting their systems.

"The biggest defence is to have any keys, especially those used to authenticate to remote machines and certainly internet facing ones, require a passphrase to use," advised Sans researcher John Bambenek.

"Check your logs, especially if you use SSH key-based auth, to identify accesses from remote machines that have no business accessing you."

Bambenek also recommends that users fully patch their systems to cover any vulnerabilities which could make the SSH keys easier to obtain.

Copyright © 2008 vnunet.com

   


Ads by Google


Thoughts on this article? Add a comment below.
Be the first to comment on this article.

Report this comment as offensive:

   * Indicates information we require to process your submission.

Name: *
Email: *
Reason for offense: *
Your report will not be displayed.  
Name:
*
 
Email:
(will not be displayed)
*
 
Comment:
(HTML not permitted)
*
 
Validation
*

Enter the code you see below:

 

 
 
 
 
 


Tripwire - Click here to win an iTouch



Product Reviews

Star Rating
The Lieberman Software Enterprise Random Pass­word Manager is a full-on password manager and randomiser for...
Star Rating
Proginet SecurForce is a little bit of a horse of a different color for this month's Group Test.
Star Rating
On the surface, RoboForm Enterprise starts out looking like a single sign-on product, but that is just on the...
Star Rating
The Symark PowerBroker is a policy-driven, privileged access control application.
Star Rating
The Symark PowerKeeper is a hardened appliance. It comes with a sealed operating system that provides a...
iTnews 2009 Job Survey

TopTopics
(28209) -  top
(4066) -  microsoft
(3289) -  acma
(2662) -  company
(2634) -  terria
(2539) -  telstra
(2371) -  broadband
(2232) -  data
(2218) -  content
(2027) -  isp
(1807) -  nbn
(1667) -  internode
(1649) -  filtering
(1530) -  voip
(1516) -  centre