FYI...
SSHD rootkit in the wild
-
https://isc.sans.edu...l?storyid=15229
Last Updated: 2013-02-22 18:32:22 UTC
"UPDATE: Over the night (depending on where you live), a lot of things happened... cPanel also
posted a notice to their users that they have been compromised... keep in mind – if your servers are infected with the SSHD rootkit, the attackers will get your passwords/keys *anyway*... So make sure that you check if your server has been compromised and that you clean it accordingly..."
-
https://isc.sans.edu...d/15229#comment
Fri Feb 22 2013, 01:49 - "... just in from cpanel: Salutations... cPanel, Inc. has discovered that one of the servers we utilize in the technical support department
has been compromised. While we do not know if your machine is affected, you should change your root level password if you are not already using ssh keys. If you are using an unprivileged account with "sudo" or "su" for root logins, we recommend you change the account password. Even if you are using ssh keys we still recommend rotating keys on a regular basis. As we do not know the exact nature of this compromise we are asking for customers to
take immediate action on their own servers. cPanel's security team is continuing to investigate the nature of this security issue..."
-
http://atlas.arbor.n...dex#-1814325122
Elevated Severity
Feb 26, 2013
Source:
http://arstechnica.c...mediate-action/
Feb 23 2013
-
http://blog.sucuri.n...ompromised.html
Feb 22, 2013
Edited by AplusWebMaster, 01 March 2013 - 05:49 AM.