Padlock
A new rootkit attack is attempting to steal SSH keys

Stolen SSH keys used for attacks

Linux keys harvested by hackers

Written by Shaun Nichols in San Francisco

Security experts are warning of a new series of Linux attacks that use stolen Secure Shell (SSH) keys.

The SSH protocol is used as a system for securely communicating between networked machines. The system was first designed as a replacement for the less-secure Telnet protocol.

The attack is part of a malware rootkit known as Phalanx2. According to an advisory from the US Computer Emergency Response Team (US-CERT,) the rootkit is a derivation of an older piece of malware and stores itself in a directory known as " /etc/khubd.p2/" which can only be accessed through the "cd" command.

Once installed, the malware scours a user's computer for vulnerable SSH keys and then attempts to use the data to carry out attacks on any connected systems.

Researchers note that the attack does not attempt to steal or use stolen keys that require passwords, leaving administrators with a good method for protecting their systems.

"The biggest defence is to have any keys, especially those used to authenticate to remote machines and certainly internet facing ones, require a passphrase to use," advised Sans researcher John Bambenek.

"Check your logs, especially if you use SSH key-based auth, to identify accesses from remote machines that have no business accessing you."

Bambenek also recommends that users fully patch their systems to cover any vulnerabilities which could make the SSH keys easier to obtain.

  • Have your say
  • Send to a friend
  • Print this
  • Share

reader comments

related articles

Homer SimpsonSecurity

Homer Simpson spreading malware

Web 2.d'oh! 12 Jul 2008

 

Hackers look to 'hardware viruses'

Malicious circuits much more difficult to detect 01 May 2008

Rise of the rootkits

Stealth malware dodges popular security products 13 Dec 2007

Storm worm back with a vengeance

Quarter of all detected threats during August, says BitDefender 10 Sep 2007

Cisco issues security advisory for UC products

Unified Communications Manager and Unified Presence get fixes 25 Aug 2010

RSA 2010: Researchers dissect ZeuS botnet blueprint

Malware startup costs put at a mere $2,500 04 Mar 2010

Cyber crooks net €300,000 in 22 days

Malware writers reap big reward from bank Trojan 01 Oct 2009

related white papers

today's top stories

Interview: Jos Creese, chief information officer, Socitm

Head of Socitm, the body for local authority IT professionals, discusses how to get the most from IT services at a time when budgets are being cut to the bone. Dawinderpal Sahota listens in 09 Sep 2010

Implementing cloud computing

UK firms are looking for on-demand, pay-as-you-go IT services, applications and infrastructure, writes Martin Courtney 08 Sep 2010

When business brains turn to crime

Cyber criminals are far better organised and more sophisticated than most legitimate e-commerce operations, writes Stuart Sumner 08 Sep 2010

Copyright agreement draft leaked again

ACTA workings published after Washington DC negotiating round 07 Sep 2010

Lloyd's Of London takes Facebook to the board

Peter Hambling, CIO of Lloyd’s of London, the venerable insurer, has made Facebook a priority for customer communications that required board approval.... 07 Sep 2010

Advertisement

Best practices to secure and protect backup data
Exploding the myths about data security and backup encryption

Using data integration to drive down costs and increase profits
This paper outlines why data integration is an important weapon in an enterprise’s competitive arsenal

Advertisement

Citrix

Keep up to date with the latest products, services and technologies from the world's leading IT companies; IThound.com brings you thousands of white papers, case studies and analyst reports.

Advertisement

Newsletter signup

Sign up for our range of FREE newsletters:

More available - click 'submit' to view

Existing User

Newsletter user login:

Jobs

Related jobs

Job of the week

Job alerts

Sign up here

Find your next job

IT Salary Checker

Check salary here

Advertisement

Latest poll

The Chinese Market

The Chinese Market

Is your company considering expansion into the Chinese market?

View poll results

Latest audio and video articles

A microphoneAudio

Computing Podcast: Tech Talk episode 5

Join Tech Talk for an overview of the week's top IT stories, and a debate on IT self-service. Will it provide value? 27 Aug 2010

A microphoneAudio

Computing podcast: Tech Talk episode 4

Join Tech Talk for an overview of the week's top IT stories, and a debate on IT skills. Is the UK slipping behind? 20 Aug 2010

Latest in-depth articles

Picture of Google logoAnalysis

Will IPv6 boost search engine rankings or is that wishful thinking?

Will search engine providers consider web-server IPv6 support to rank content in the future? 09 Sep 2010

Jos CreeseFeatures

Interview: Jos Creese, chief information officer, Socitm

Head of Socitm, the body for local authority IT professionals, discusses how to get the most from IT services at a time when budgets are being cut to the bone. Dawinderpal Sahota listens in 09 Sep 2010

Primary Navigation