SSH Key-Based Attacks
Wednesday, September 17, 2008
Watch out. US-CERT (United States Computer Emergency Readiness Team) reported a rising flood of active attacks against Linux-based computing infrastructures using compromised SSH keys. The attack appears to use stolen SSH keys to gain access to a system, and then uses local kernel exploits to gain root access. Once root access has been obtained, a rootkit known as "phalanx2" is installed. Click here to read the full report.