Attack on Linux

This is a discussion on Attack on Linux within the Suse forums, part of the Linux category; The U.S. Computer Emergency Readiness Team (CERT) has issued a warning for what it calls “active attacks” against Linux-based computing infrastructures using compromised SSH keys. The attack appears to initially ...

Go Back   Unix Linux Forum > Unix > Linux > Suse

FixUnix.com - Unix Linux Forums

Unix Content Register FAQ Calendar Search Today's Posts Mark Forums Read
  #1  
Old 08-27-2008, 01:13 PM
Default Attack on Linux

The U.S. Computer Emergency Readiness Team (CERT) has issued a warning
for what it calls “active attacks” against Linux-based computing
infrastructures using compromised SSH keys.

The attack appears to initially use stolen SSH keys to gain access to a
system, and then uses local kernel exploits to gain root access. Once
root access has been obtained, a rootkit known as “phalanx2? is
installed, US-CERT said in a note on its current activity site.

So what is being done to thwart this?


--
Blattus Slafaly ? 3 7/8
Reply With Quote
  #2  
Old 08-27-2008, 03:28 PM
Default Re: Attack on Linux

On Wed, 27 Aug 2008 13:13:29 -0400, Blattus Slafaly typed this message:

> The U.S. Computer Emergency Readiness Team (CERT) has issued a warning
> for what it calls “active attacks” against Linux-based computing
> infrastructures using compromised SSH keys.
>
> The attack appears to initially use stolen SSH keys to gain access to a
> system, and then uses local kernel exploits to gain root access. Once
> root access has been obtained, a rootkit known as “phalanx2? is
> installed, US-CERT said in a note on its current activity site.
>
> So what is being done to thwart this?


Are you running updated chkrootkit? Is this the list of compromised keys
from Fedora Project?
Reply With Quote
  #3  
Old 08-28-2008, 04:19 PM
Default Re: Attack on Linux

* Moe Trin wrote in alt.os.linux.suse:

> Accoring to a post to the Usenet newsgroup 'comp.os.linux.security'
> yesterday, John E. Davis (author of slang, slsh, and the slrn news tool)
> stated that chkrootkit didn't detect this root kit (surprise, surprise).
> That post included a URL to a script he created that was able to detect
> the 'phalanx2' rootkit. He's using a somewhat different technique from
> the hints mentioned by CERT/
>


FYI:

Message-ID:

--
David
Reply With Quote
Reply

Thread Tools


All times are GMT -5. The time now is 10:53 PM.

In an effort to better serve ads to our visitors, cookies are used on Fixunix.com. For more information, check out our Privacy Policy.

Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Search Engine Friendly URLs by vBSEO 3.2.0
Ad Management by RedTyger