Padlock
A new rootkit attack is attempting to steal SSH keys

Stolen SSH keys used for attacks

Linux keys harvested by hackers

Written by Shaun Nichols in San Francisco

Security experts are warning of a new series of Linux attacks that use stolen Secure Shell (SSH) keys.

The SSH protocol is used as a system for securely communicating between networked machines. The system was first designed as a replacement for the less-secure Telnet protocol.

Advertisement

The attack is part of a malware rootkit known as Phalanx2. According to an advisory from the US Computer Emergency Response Team (US-CERT,) the rootkit is a derivation of an older piece of malware and stores itself in a directory known as " /etc/khubd.p2/" which can only be accessed through the "cd" command.

Once installed, the malware scours a user's computer for vulnerable SSH keys and then attempts to use the data to carry out attacks on any connected systems.

Researchers note that the attack does not attempt to steal or use stolen keys that require passwords, leaving administrators with a good method for protecting their systems.

"The biggest defence is to have any keys, especially those used to authenticate to remote machines and certainly internet facing ones, require a passphrase to use," advised Sans researcher John Bambenek.

"Check your logs, especially if you use SSH key-based auth, to identify accesses from remote machines that have no business accessing you."

Bambenek also recommends that users fully patch their systems to cover any vulnerabilities which could make the SSH keys easier to obtain.

Related whitepapers

Related jobs

Do you agree?

IT white papers

Search vnunet IThound

Top categories

Job of the week

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Hiring now on ComputingCareers:

Related IT jobs

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Advertisement

Advertisement

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Enter email address to edit your newsletter preferences

Watch

Shaun Nichols and Iain Thomson

21 Nov 2008

9.11 MBPodcast Special: Views from the Valley More...

Podcast

20 Nov 2008

9.43 MBComputing podcast: Europol's data sharing woes; credit card protection at Cotton Traders More...

Shaun Nichols and Iain Thomson

14 Nov 2008

7.73 MBPodcast Special: Views from the Valley More...

Poll

Data breaches

Data breaches

What is the best way to ensure firms take data breaches seriously?

Previous poll results

Spotlight

Google Chrome

Google may pre-install Chrome browser

Search giant investigating OEM deals   More...

phil muncaster

Video: vnunet.com weekly debrief

Phil Muncaster and BusinessGreen.com editor James Murray discuss the week's...  More...

Ofcom HQ

UK leading European technology charge

Ofcom report reveals convergence trend   More...

CA World 2008

vnunet.com analysis: CIOs outline IT spending priorities

IT chiefs advise looking for high-value projects rather than suspending...  More...

Primary Navigation