FEATURED VIDEO

Sponsored By:


SLIDE SHOWS
ChannelWeb's Top 25 Execs of 2008 know that reading is fundamental. Here are their picks for books to feed your brain.
There were plenty of high-powered movers and shakers that made a big impact on the channel in 2008. Here's a look at who made our list of the 25 most influential.
It's time again to agonize over what to get the techie in your life. With the holidays closing in fast, here are 25 gift ideas sure to wow any techie.
INSIDE CHANNELWEB
techcareers logo Search Jobs:


  

Post Resume|Employers

Recent Post:


Regional Desktop Coordinator
BP seeking Regional Desktop Coordinator in Houston, TX
spacer

US-CERT Confirms Attacks Using Stolen SSH Keys


By Kevin McLaughlin, ChannelWeb
7:52 PM EDT Wed. Aug. 27, 2008
US-CERT on Wednesday confirmed that attackers are actively targeting Linux-based computing infrastructures, using stolen SSH keys to gain access to systems and install a rootkit known as "phalanx2".

According to US-CERT, phalanx2 bears certain similarities to an older rootkit called "phalanx," and is set up to steal SSH keys and send them to attackers, who then turn around and use them to break into other sites.

This type of attack can be easily detected and blocked by network or host based IPS, according to Andrew Plato, president at Anitian Enterprise Security, a security specialist in Beaverton, Ore.

"Any company with live hosts on the Internet should have IPS. It's a proven security technology that can bridge the gap between the outbreak of a new attack and the time to patch systems," Plato said.

US-CERT is advising organizations to identify and examine systems where SSH keys are used in automated processes and to examine Internet-facing systems to ensure that their patches are up to date.

If a system turns up that has been compromised by Phalanx2, US-CERT recommends that administrators disable key-based SSH authentication where possible; perform an audit of all SSH keys on compromised systems; and alert key owners that their keys may have been compromised.

There has been a recent uptick in the number of Linux-related attacks, and a fairly large number of Linux users still believe Linux is immune from a security standpoint, Plato said.

"When they experience their first compromise, it can be a real eye opener to the reality of Linux security. A poorly managed or secured Linux system isn't any safer than a poorly managed Windows box," Plato said.

Last week, Red Hat released a security advisory and an update to OpenSSH packages relating to its Red Hat Enterprise Linux software after hackers attempted to break into servers belonging to the company and the community-supported Fedora Linux project earlier this month.

In May, security expert Luciano Bello warned of a critical vulnerability in the way SSH keys are generated, an issue that affected Debian systems and Debian-based machines, including Ubuntu, its variants, and Knoppix.


RATE THIS ARTICLE Worse 1 2 3 4 5 Better
CHANNELWEB MARKETSPACE >> (Sponsored Links)
Channelweb : Promofinder
FEATURED PROMOTIONS
90% OFF Aladdin SafeWord Starter Pack - Act Now!!
Make more money with SafeWord and Aladdin now that we've joined teams. Order a SafeWord Two-Factor Authentication Starter P...
Get More in Q4 from Kaspersky Lab
Sell Kaspersky products and earn dollars for every sale of 10 or more nodes. That’s right! Every sale you make will put extra...
LATEST NEWS >>
December 01, 2008 06:50 PM
December 01, 2008 04:19 PM
December 01, 2008 03:40 PM
December 01, 2008 11:55 AM
December 01, 2008 10:39 AM
RELATED BLOG >>
Photo
The Test Center's most recent threat watch.
ADVERTISEMENT




CHANNEL SERVICES >>