Welcome Guest to What the Tech! ( Log In | Register ) We specialize in the removal of malicious software (malware), but here you'll find free help and support for all your tech questions. We invite you to ask questions, share experiences, and learn. Explore our message boards, or register now to post messages of your own. Please Start Here. Register today (registration removes advertising)
![]() ![]() |
Aug 26 2008, 06:33 PM
Post
#1
|
|
![]() AplusWebMaster ![]() ![]() ![]() ![]() ![]() Group: Authentic Member Posts: 3,584 Joined: 30-December 03 From: USA Member No.: 1,643 Operating System: WinXP |
FYI...
- http://www.us-cert.gov/current/#ssh_key_based_attacks August 26, 2008 - "US-CERT is aware of active attacks against linux-based computing infrastructures using compromised SSH keys. The attack appears to initially use stolen SSH keys to gain access to a system, and then uses local kernel exploits to gain root access. Once root access has been obtained, a rootkit known as "phalanx2" is installed. Phalanx2 appears to be a derivative of an older rootkit named "phalanx". Phalanx2 and the support scripts within the rootkit, are configured to systematically steal SSH keys from the compromised system. These SSH keys are sent to the attackers, who then use them to try to compromise other sites and other systems of interest at the attacked site. Detection of phalanx2 as used in this attack may be performed as follows: * "ls" does not show a directory "/etc/khubd.p2/", but it can be entered with "cd /etc/khubd.p2". * "/dev/shm/" may contain files from the attack. * Any directory named "khubd.p2" is hidden from "ls", but may be entered by using "cd". * Changes in the configuration of the rootkit might change the attack indicators listed above. Other detection methods may include searching for hidden processes and checking the reference count in "/etc" against the number of directories shown by "ls". US-CERT encourages administrators to perform the following actions to help mitigate the risks: * Proactively identify and examine systems where SSH keys are used as part of automated processes. These keys will typically not have passphrases or passwords. * Encourage users to use the keys with passphrase or passwords to reduce the risk if a key is compromised. * Review access paths to internet facing systems and ensure that systems are fully patched. If a compromise is confirmed, US-CERT recommends the following actions: * Disable key-based SSH authentication on the affected systems, where possible. * Perform an audit of all SSH keys on the affected systems. * Notify all key owners of the potential compromise of their keys. US-CERT will provide additional information as it becomes available." |
|
|
|
Aug 27 2008, 04:27 AM
Post
#2
|
|
![]() AplusWebMaster ![]() ![]() ![]() ![]() ![]() Group: Authentic Member Posts: 3,584 Joined: 30-December 03 From: USA Member No.: 1,643 Operating System: WinXP |
FYI...
- http://isc.sans.org/diary.html?storyid=4937 Last Updated: 2008-08-26 21:52:26 UTC - "...Sources of compromised keys could include the weak key vulnerability in Debian-based systems a few months ago, so if you haven't updated and replaced those keys, you ought to do so now. The biggest defense is to have any keys, especially those used to authenticate to remote machines and certainly internet facing ones, require a passphrase to use. Check your logs, especially if you use SSH key-based auth, to identify accesses from remote machines that have no business accessing you. If you have IPs, that would be good. To detect if you have Phalanx2, look for /etc/khubd.p2/ (access by cd, not ls) or any directory that is called "khubd.p2". /dev/shm/ may contain files from the attack as well. Tripwire, AIDE and friends should also be able to detect filesystem changes." |
|
|
|
![]() ![]() |
Similar Topics
| Topic Title | Replies | Topic Starter | Views | Last Action | |||
|---|---|---|---|---|---|---|---|
![]() |
2 | helpme67 | 45 | 29th November 2008 - 03:45 PM Last post by: LDTate |
|||
![]() |
0 | AplusWebMaster | 48 | 31st October 2008 - 03:27 PM Last post by: AplusWebMaster |
|||
![]() |
1 | PaPa-Smurf | 142 | 30th September 2008 - 08:51 PM Last post by: Ztruker |
|||
![]() |
69 | leet_alex | 1,333 | 22nd September 2008 - 03:00 AM Last post by: Troy |
|||
|
Time is now: 1st December 2008 - 12:33 PM |