Home > Linux, SSH > Linux under attack: Compromised SSH keys lead to rootkit

Linux under attack: Compromised SSH keys lead to rootkit

The U.S. Computer Emergency Readiness Team (CERT) has issued a warning for what it calls “active attacks” against Linux-based computing infrastructures using compromised SSH keys.

The attack appears to initially use stolen SSH keys to gain access to a system, and then uses local kernel exploits to gain root access. Once root access has been obtained, a rootkit known as “phalanx2″ is installed, US-CERT said in a note on its current activity site.

Read the full article here

Categories: Linux, SSH Tags:
  1. No comments yet.
  1. No trackbacks yet.
-->

Bad Behavior has blocked 19 access attempts in the last 7 days.