Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > comp.os.linux.advocacy > #165938 > unrolled thread

SSHD rootkit heads up

Started byChris Ahlstrom <OFeem1987@teleworm.us>
First post2013-02-22 06:51 -0500
Last post2013-02-22 19:51 +0000
Articles 14 on this page of 34 — 19 participants

Back to article view | Back to comp.os.linux.advocacy


Contents

  SSHD rootkit heads up Chris Ahlstrom <OFeem1987@teleworm.us> - 2013-02-22 06:51 -0500
    Re: SSHD rootkit heads up chrisv <chrisv@nospam.invalid> - 2013-02-22 09:29 -0600
    Re: SSHD rootkit heads up Lusotec <nomail@nomail.not> - 2013-02-22 16:22 +0000
      Re: SSHD rootkit heads up "Cola Zealot" <Cola_Zealot@fuckoff.com> - 2013-02-22 19:27 +0100
        Re: SSHD rootkit heads up JEDIDIAH <jedi@nomad.mishnet> - 2013-02-22 13:50 -0600
          Re: SSHD rootkit heads up DFS <nospam@dfs.com> - 2013-02-22 15:11 -0500
          Re: SSHD rootkit heads up Snit <usenet@gallopinginsanity.com> - 2013-02-22 21:11 -0700
        Re: SSHD rootkit heads up RayLopez99 <raylopez88@gmail.com> - 2013-02-22 16:07 -0800
      Proprietary software vulnerability causes rootkit injection Homer <usenet@slated.org> - 2013-02-23 03:57 +0000
        Re: Proprietary software vulnerability causes rootkit injection TomB <tommy.bongaerts@gmail.com> - 2013-02-23 06:46 +0000
          Re: Proprietary software vulnerability causes rootkit injection Snit <usenet@gallopinginsanity.com> - 2013-02-23 10:03 -0700
            Re: Proprietary software vulnerability causes rootkit injection TomB <tommy.bongaerts@gmail.com> - 2013-02-24 10:44 +0000
          No conclusive evidence as to what causes rootkit injection "Ezekiel" <zeke@nosuchemail.com> - 2013-02-23 18:05 -0500
            Re: No conclusive evidence as to what causes rootkit injection TomB <tommy.bongaerts@gmail.com> - 2013-02-24 10:26 +0000
              Re: No conclusive evidence as to what causes rootkit injection "Ezekiel" <zeke@nosuchemail.com> - 2013-02-24 08:29 -0500
        Re: Proprietary software vulnerability causes rootkit injection Snit <usenet@gallopinginsanity.com> - 2013-02-23 10:04 -0700
          Re: Proprietary software vulnerability causes rootkit injection "Cola Zealot" <Cola_Zealot@fuckoff.com> - 2013-02-23 22:39 +0100
            Re: Proprietary software vulnerability causes rootkit injection Snit <usenet@gallopinginsanity.com> - 2013-02-23 15:25 -0700
              Re: Proprietary software vulnerability causes rootkit injection "Cola Zealot" <Cola_Zealot@fuckoff.com> - 2013-02-24 11:34 +0100
                Re: Proprietary software vulnerability causes rootkit injection fuyang <cei@mail.huafeng.cma.gov.cn> - 2013-02-24 14:00 +0100
                  Re: Linux vulnerability causes rootkit injection "Cola Zealot" <Cola_Zealot@fuckoff.com> - 2013-02-24 16:42 +0100
                    Re: Linux vulnerability causes rootkit injection Hadron<hadronquark@gmail.com> - 2013-02-24 16:48 +0100
                      Re: Linux vulnerability causes rootkit injection "Ezekiel" <zeke@nosuchemail.com> - 2013-02-24 10:55 -0500
                        Re: Linux vulnerability causes rootkit injection GreyCloud <mist@cumulus.com> - 2013-02-24 09:34 -0700
                          Re: Linux vulnerability causes rootkit injection Denis McMahon <denismfmcmahon@gmail.com> - 2013-03-07 05:45 +0000
                            Re: Linux vulnerability causes rootkit injection Jim Beard <jdbeard@patriot.net> - 2013-03-07 10:05 -0500
                              Re: Linux vulnerability causes rootkit injection William Poaster <wp@induh-vidual.net> - 2013-03-07 23:02 +0000
                                Re: Linux vulnerability causes rootkit injection flatfish+++ <phlatphish@yahoo.com> - 2013-03-07 18:22 -0500
                                  Re: Linux vulnerability causes rootkit injection GreyCloud <mist@cumulus.com> - 2013-03-07 22:33 -0700
                                Re: Someone else did, stupid jerk.  You aren't very bright. GreyCloud <mist@cumulus.com> - 2013-03-07 22:30 -0700
                                Re: Linux vulnerability causes rootkit injection Hadron<hadronquark@gmail.com> - 2013-03-08 08:05 +0100
                            Re: Linux vulnerability causes rootkit injection GreyCloud <mist@cumulus.com> - 2013-03-07 12:36 -0700
    Re: SSHD rootkit heads up TomB <tommy.bongaerts@gmail.com> - 2013-02-22 17:56 +0000
    Re: SSHD rootkit heads up owl <owl@rooftop.invalid> - 2013-02-22 19:51 +0000

Page 2 of 2 — ← Prev page 1 [2]


#166341 — Re: Linux vulnerability causes rootkit injection

From"Cola Zealot" <Cola_Zealot@fuckoff.com>
Date2013-02-24 16:42 +0100
SubjectRe: Linux vulnerability causes rootkit injection
Message-ID<512a34df$0$12000$6e1ede2f@read.cnntp.org>
In reply to#166296
An idiot who calls himself fuyang wrote:
> On 24.02.2013 11:34, Cola Zealot wrote:
>> Snit wrote:
>>> On 2/23/13 2:39 PM, in article
>>> 512936e2$0$12000$6e1ede2f@read.cnntp.org, "Cola Zealot"
>>> <Cola_Zealot@fuckoff.com> wrote:
>>>
>>>> Snit wrote:
>>>>> On 2/22/13 8:57 PM, in article m9rlv9-rrv.ln1@sky.matrix, "Homer"
>>>>> <usenet@slated.org> wrote:
>>>>>
>>>>>> Verily I say unto thee that Lusotec spake thusly:
>>>>>>>
>>>>>>> Chris Ahlstrom wrote:
>>>>>>>
>>>>>>>>    https://isc.sans.edu/diary/SSHD+rootkit+in+the+wild/15229
>>>>>>>>
>>>>>>>>    SSHD rootkit in the wild
>>>>>>>>    Published: 2013-02-21,
>>>>>>>>    Last Updated: 2013-02-22 09:23:59 UTC
>>>>>>>>
>>>>>>>>    There are a lot of discussions at the moment about a SSHD
>>>>>>>>    rootkit hitting mainly RPM based Linux distributions.
>>>>>>>>    Thanks to our reader unSpawn, we received a bunch of samples
>>>>>>>>    of the rootkit. The rootkit is actually a trojanized library
>>>>>>>>    that links with SSHD and does *a lot* of nasty things to the
>>>>>>>> system.
>>>>>>>
>>>>>>> Here are some more interesting information on that.
>>>>>>> http://www.webhostingtalk.com/showthread.php?t=1235797
>>>>>>
>>>>>> From the available evidence it seems this security breach was
>>>>>> cause by a proprietary application called CPanel, a notoriously
>>>>>> insecure Web interface for configuring servers.
>>>>>>
>>>>>> Yet another good reason to choose Free Software.
>>>>>
>>>>> And yet you choose G+ which is a proprietary solution.
>>>>
>>>> No problem for Homer.
>>>> As long as Microsoft is not involved, proprietary solutions are
>>>> fine with him, since he's a raging hypocrite who hoarded money from
>>>> proprietary software his entire career.
>>>
>>> MS of Apple - the two companies who he envies the success of.
>>
>> Creepy Ahlstrom, Homer, Rexford kingmaker and Peter Kohlmann have
>> many things in common.
>> They envy the success of (former) CEO's and huge innovators like
>> Ballmer, Jobs, Cook, Gates because these linturds have never achieved
>> anything even a tiny bit similar in life and never will.
>> This has turned them in angry old men and raving anti-corporate
>> trolls. Poor  Linturds with their failed crap careers!
>
> You defend companies, that let things like this happen?
>
> http://www.theregister.co.uk/2013/02/23/microsoft_azure_back_online/
>
> You obey "huge innovators" that sell stolen ideas? You prefer to use
> software that keeps users imprisonated?

And of course you obey your masters at Google "a Linux Company" who sells a 
crappy £1049 / $1604 / € 1216 laptop like this!
<quote>
Google is offering Pixel buyers an unprecedented 1 terabyte of cloud storage 
for three years. The catch - and it's a big one - is that after those three 
years, you're paying $50 per month to keep photos, GIFs, or whatever else 
you right-click on stored in Google's cloud. That's a lot of money if you 
don't plan on buying a replacement within that three-year window.
</quote> 

[toc] | [prev] | [next] | [standalone]


#166345 — Re: Linux vulnerability causes rootkit injection

FromHadron<hadronquark@gmail.com>
Date2013-02-24 16:48 +0100
SubjectRe: Linux vulnerability causes rootkit injection
Message-ID<qvy5edd87j.fsf@news.eternal-september.org>
In reply to#166341
"Cola Zealot" <Cola_Zealot@fuckoff.com> writes:

>
> And of course you obey your masters at Google "a Linux Company" who sells a
> crappy £1049 / $1604 / € 1216 laptop like this!
> <quote>
> Google is offering Pixel buyers an unprecedented 1 terabyte of cloud storage for
> three years. The catch - and it's a big one - is that after those three years,
> you're paying $50 per month to keep photos, GIFs, or whatever else you
> right-click on stored in Google's cloud. That's a lot of money if you don't plan
> on buying a replacement within that three-year window.
> </quote> 
>
>

50 a MONTH!?!?!??!?!? Holy shit.


-- 
A certain COLA "advocate" faking his user-agent in order to pretend to be a Linux 
user: User-Agent: Outlook 5.5 (WinNT 5.0), User-Agent: slrn/0.9.8.0
(Linux), Message-ID: <wPGdnd3NnOM0ACfdRVn-hw@comcast.com>

[toc] | [prev] | [next] | [standalone]


#166348 — Re: Linux vulnerability causes rootkit injection

From"Ezekiel" <zeke@nosuchemail.com>
Date2013-02-24 10:55 -0500
SubjectRe: Linux vulnerability causes rootkit injection
Message-ID<kgdd30$1jf$1@dont-email.me>
In reply to#166345
"Hadron" <hadronquark@gmail.com> wrote in message 
news:qvy5edd87j.fsf@news.eternal-september.org...
> "Cola Zealot" <Cola_Zealot@fuckoff.com> writes:
>
>>
>> And of course you obey your masters at Google "a Linux Company" who sells 
>> a
>> crappy Ł1049 / $1604 / ? 1216 laptop like this!
>> <quote>
>> Google is offering Pixel buyers an unprecedented 1 terabyte of cloud 
>> storage for
>> three years. The catch - and it's a big one - is that after those three 
>> years,
>> you're paying $50 per month to keep photos, GIFs, or whatever else you
>> right-click on stored in Google's cloud. That's a lot of money if you 
>> don't plan
>> on buying a replacement within that three-year window.
>> </quote>
>>
>>
>
> 50 a MONTH!?!?!??!?!? Holy shit.
>

Here's a comment from a article about this lower laptop:

<quote>
"I'm staggered at the depths of stupid Google displays with this thing.
Basically, you pay Google a snazzy premium for a snazzy dumb terminal to
suck up personal data so Google can mine it and make more money off you."
</quote>

In other words, you get to pay Google $50 a month for the privilege of them 
sucking in every bit of personal data you have and then using your data to 
make them money.

-- 
> Just picked up the 8-gig model (iPhone)

Yeah, fine, cute toy and all, but some gimboid up there is trying to fob it 
off as a "wowee" when in fact, it's more of a "gee whiz" - as in "Gee whiz, 
now I can store phone numbers for 180 million people... and the two friends 
I actually have."

Kelsey Bjarnason - Failing to understand smartphone basics
<dn0pn4-8vs.ln1@spanky.localhost.net>


[toc] | [prev] | [next] | [standalone]


#166362 — Re: Linux vulnerability causes rootkit injection

FromGreyCloud <mist@cumulus.com>
Date2013-02-24 09:34 -0700
SubjectRe: Linux vulnerability causes rootkit injection
Message-ID<Bpudnc0OZsOK3LfMnZ2dnUVZ_jCdnZ2d@bresnan.com>
In reply to#166348
On 2/24/2013 8:55 AM, Ezekiel wrote:
> "Hadron" <hadronquark@gmail.com> wrote in message
> news:qvy5edd87j.fsf@news.eternal-september.org...
>> "Cola Zealot" <Cola_Zealot@fuckoff.com> writes:
>>
>>>
>>> And of course you obey your masters at Google "a Linux Company" who sells
>>> a
>>> crappy £1049 / $1604 / ? 1216 laptop like this!
>>> <quote>
>>> Google is offering Pixel buyers an unprecedented 1 terabyte of cloud
>>> storage for
>>> three years. The catch - and it's a big one - is that after those three
>>> years,
>>> you're paying $50 per month to keep photos, GIFs, or whatever else you
>>> right-click on stored in Google's cloud. That's a lot of money if you
>>> don't plan
>>> on buying a replacement within that three-year window.
>>> </quote>
>>>
>>>
>>
>> 50 a MONTH!?!?!??!?!? Holy shit.
>>
>
> Here's a comment from a article about this lower laptop:
>
> <quote>
> "I'm staggered at the depths of stupid Google displays with this thing.
> Basically, you pay Google a snazzy premium for a snazzy dumb terminal to
> suck up personal data so Google can mine it and make more money off you."
> </quote>
>
> In other words, you get to pay Google $50 a month for the privilege of them
> sucking in every bit of personal data you have and then using your data to
> make them money.
>
Any time they start touting the Cloud storage... don't buy and don't do 
it.  Matter of fact... RUN!

[toc] | [prev] | [next] | [standalone]


#168320 — Re: Linux vulnerability causes rootkit injection

FromDenis McMahon <denismfmcmahon@gmail.com>
Date2013-03-07 05:45 +0000
SubjectRe: Linux vulnerability causes rootkit injection
Message-ID<kh99hd$16u$1@dont-email.me>
In reply to#166362
On Sun, 24 Feb 2013 09:34:31 -0700, GreyCloud wrote:

> Any time they start touting the Cloud storage... don't buy and don't do
> it.  Matter of fact... RUN!

I thought the whole point of cloud storage was to provide all government 
agencies globally with a single point of contact for a warrantless search 
of your complete life.

Or did I miss something?

-- 
Denis McMahon, denismfmcmahon@gmail.com

[toc] | [prev] | [next] | [standalone]


#168367 — Re: Linux vulnerability causes rootkit injection

FromJim Beard <jdbeard@patriot.net>
Date2013-03-07 10:05 -0500
SubjectRe: Linux vulnerability causes rootkit injection
Message-ID<_ZednbTWkIEpMaXMnZ2dnUVZ_tudnZ2d@posted.lerostechnologies>
In reply to#168320
On 03/07/2013 12:45 AM, Denis McMahon wrote:
> On Sun, 24 Feb 2013 09:34:31 -0700, GreyCloud wrote:
>
>> Any time they start touting the Cloud storage... don't buy and don't do
>> it.  Matter of fact... RUN!
>
> I thought the whole point of cloud storage was to provide all government
> agencies globally with a single point of contact for a warrantless search
> of your complete life.
>
> Or did I miss something?

You missed a few things.

Probably the most important is backup, which few lusers do 
despite decades of experience demonstrating its importance. 
Depending on which cloud you store stuff in, you not only get 
off-site backup but will likely get multiple backups as well.

Second, cracking and looting a home luser's machine is trivial in 
maybe 70-85 percent of cases.  Storage in the cloud will not 
reduce vulnerability of the home machine, but storage in the 
cloud is certainly  a minor increase in vulnerability (vulnerable 
to some extent in a second place, in addition to totally 
vulnerable in the first place, for most).  Those who keep their 
important stuff in the cloud, deleting it from the home machine 
and getting it back when needed, have a means to minimize 
vulnerability to the amateurs and script kiddies.

Third, while neither the cloud nor the home machine are safe from 
the pros, the bigger the cloud grows the greater the difficulty 
for the cracker when it comes time to sort and select from 
whatever was grabbed when a crack succeeds.  There is simply more 
stuff they have to sort through.

The only downside is that data once uploaded to the cloud could 
be kept forever, or until bit rot sets in.  I sort of suspect the 
cost of keeping storage disks spinning forever once written to, 
and of shifting data to other forms of permanent storage, is 
enough to discourage cloud operators for keeping everything forever.

Benefits to the government are incidental, and depend on the 
government involved.  If the pros decide to target you, they will 
likely get what they want, regardless of cloud or home machine or 
whatever.  Why increase the cost of government (and therefore the 
amount of taxes necessary to pay for it) by making government 
access to your data inconvenient?

The goal in computer security (for most -- a few with special 
requirements excepted) is to make it costly in time, effort, and 
hopefully money to crack your machine(s), and thereby reduce the 
incentive to target them.  Make it difficult enough, and the 
nasties will go after someone else.  (You don't have to be the 
fastest gazelle to escape the lion, just faster than the slowest 
gazelle between the lion and you.)

Don't be low-hanging fruit, easily available for the picking.

Cheers!

jim b.




-- 
UNIX is not user unfriendly; it merely
      expects users to be computer-friendly.

[toc] | [prev] | [next] | [standalone]


#168458 — Re: Linux vulnerability causes rootkit injection

FromWilliam Poaster <wp@induh-vidual.net>
Date2013-03-07 23:02 +0000
SubjectRe: Linux vulnerability causes rootkit injection
Message-ID<isin0a-bih.ln1@wp.alpha-one.linuxorg>
In reply to#168367
Jim Beard wrote:

> On 03/07/2013 12:45 AM, Denis McMahon wrote:
>> On Sun, 24 Feb 2013 09:34:31 -0700, GreyCloud wrote:
>>
>>> Any time they start touting the Cloud storage... don't buy and don't do
>>> it.  Matter of fact... RUN!

<snip>

The GreyClod troll crossposting to comp.os.linux.security.
Wassamatter, couldn't the senile fuckwit remember which group he's
supposed to be trolling! 

<xpost to comp.os.linux.security snipped>

-- 
We are Micro$oft of Borg. You may already be assimilated.

Micro$oft, the company that makes spreading malware easy. 

Microsoft exec Ron Markezich was quoted saying that for every $1 
companies spend on Microsoft software, they need to spend $6 getting 
it to work right. -- April 2011 SanFrancisco Chronical --

"We have no intention of shipping another bloated OS and shoving 
it down the throats of our users."
-- Paul Maritz, Microsoft group vice president --

What's bad about Micro$oft:
http://www.kmfms.com/whatsbad.html

[toc] | [prev] | [next] | [standalone]


#168459 — Re: Linux vulnerability causes rootkit injection

Fromflatfish+++ <phlatphish@yahoo.com>
Date2013-03-07 18:22 -0500
SubjectRe: Linux vulnerability causes rootkit injection
Message-ID<88u0gosiidlk$.nh9l4wr30k3h.dlg@40tude.net>
In reply to#168458
On Thu, 7 Mar 2013 23:02:10 +0000, William Poaster wrote:

> Jim Beard wrote:
> 
>> On 03/07/2013 12:45 AM, Denis McMahon wrote:
>>> On Sun, 24 Feb 2013 09:34:31 -0700, GreyCloud wrote:
>>>
>>>> Any time they start touting the Cloud storage... don't buy and don't do
>>>> it.  Matter of fact... RUN!
> 
> <snip>
> 
> The GreyClod troll crossposting to comp.os.linux.security.
> Wassamatter, couldn't the senile fuckwit remember which group he's
> supposed to be trolling! 
> 
> <xpost to comp.os.linux.security snipped>

Make sure to do the same when 7 crossposts all over the place.

-- 
flatfish+++
PLEASE VISIT OUR HALL OF LINUX IDIOTS:
http://linuxidiots.blogspot.com/

[toc] | [prev] | [next] | [standalone]


#168488 — Re: Linux vulnerability causes rootkit injection

FromGreyCloud <mist@cumulus.com>
Date2013-03-07 22:33 -0700
SubjectRe: Linux vulnerability causes rootkit injection
Message-ID<yJqdnbAOtKWC5aTMnZ2dnUVZ_jednZ2d@bresnan.com>
In reply to#168459
On 3/7/2013 4:22 PM, flatfish+++ wrote:
> On Thu, 7 Mar 2013 23:02:10 +0000, William Poaster wrote:
>
>> Jim Beard wrote:
>>
>>> On 03/07/2013 12:45 AM, Denis McMahon wrote:
>>>> On Sun, 24 Feb 2013 09:34:31 -0700, GreyCloud wrote:
>>>>
>>>>> Any time they start touting the Cloud storage... don't buy and don't do
>>>>> it.  Matter of fact... RUN!
>>
>> <snip>
>>
>> The GreyClod troll crossposting to comp.os.linux.security.
>> Wassamatter, couldn't the senile fuckwit remember which group he's
>> supposed to be trolling!
>>
>> <xpost to comp.os.linux.security snipped>
>
> Make sure to do the same when 7 crossposts all over the place.
>
LOL!!!  That idiot can't even follow the thread to find out who cross 
posted.  LOL!!!  It was lusotec that cross posted.

[toc] | [prev] | [next] | [standalone]


#168487 — Re: Someone else did, stupid jerk. You aren't very bright.

FromGreyCloud <mist@cumulus.com>
Date2013-03-07 22:30 -0700
SubjectRe: Someone else did, stupid jerk. You aren't very bright.
Message-ID<8dudnWSOteQT6qTMnZ2dnUVZ_v-dnZ2d@bresnan.com>
In reply to#168458
On 3/7/2013 4:02 PM, William Poaster wrote:
> Jim Beard wrote:
>
>> On 03/07/2013 12:45 AM, Denis McMahon wrote:
>>> On Sun, 24 Feb 2013 09:34:31 -0700, GreyCloud wrote:
>>>
>>>> Any time they start touting the Cloud storage... don't buy and don't do
>>>> it.  Matter of fact... RUN!
>
> <snip>
>
> The GreyClod troll crossposting to comp.os.linux.security.
> Wassamatter, couldn't the senile fuckwit remember which group he's
> supposed to be trolling!
>
> <xpost to comp.os.linux.security snipped>
>

[toc] | [prev] | [next] | [standalone]


#168493 — Re: Linux vulnerability causes rootkit injection

FromHadron<hadronquark@gmail.com>
Date2013-03-08 08:05 +0100
SubjectRe: Linux vulnerability causes rootkit injection
Message-ID<mhppzaweup.fsf@news.eternal-september.org>
In reply to#168458
William Poaster <wp@induh-vidual.net> writes:

> Jim Beard wrote:
>
>> On 03/07/2013 12:45 AM, Denis McMahon wrote:
>>> On Sun, 24 Feb 2013 09:34:31 -0700, GreyCloud wrote:
>>>
>>>> Any time they start touting the Cloud storage... don't buy and don't do
>>>> it.  Matter of fact... RUN!
>
> <snip>
>
> The GreyClod troll crossposting to comp.os.linux.security.
> Wassamatter, couldn't the senile fuckwit remember which group he's
> supposed to be trolling! 
>
> <xpost to comp.os.linux.security snipped>

While we realise you're a bit dumb "me too" Willy, You REALLY should
learn to read headers better. This thread has been xposted about ten
depths back and it was Lusertec (an "advocate") who started i.

Poor Dumb Willy Poaster.

-- 
A certain COLA "advocate" faking his user-agent in order to pretend to be a Linux 
user: User-Agent: Outlook 5.5 (WinNT 5.0), User-Agent: slrn/0.9.8.0
(Linux), Message-ID: <wPGdnd3NnOM0ACfdRVn-hw@comcast.com>

[toc] | [prev] | [next] | [standalone]


#168433 — Re: Linux vulnerability causes rootkit injection

FromGreyCloud <mist@cumulus.com>
Date2013-03-07 12:36 -0700
SubjectRe: Linux vulnerability causes rootkit injection
Message-ID<YvidnX5yp8_OcaXMnZ2dnUVZ_t-dnZ2d@bresnan.com>
In reply to#168320
On 3/6/2013 10:45 PM, Denis McMahon wrote:
> On Sun, 24 Feb 2013 09:34:31 -0700, GreyCloud wrote:
>
>> Any time they start touting the Cloud storage... don't buy and don't do
>> it.  Matter of fact... RUN!
>
> I thought the whole point of cloud storage was to provide all government
> agencies globally with a single point of contact for a warrantless search
> of your complete life.
>
> Or did I miss something?
>
No, you didn't miss a beat.  I just won't have my backups on a cloud and 
then have it disappear.  There really isn't any point to using a cloud.

[toc] | [prev] | [next] | [standalone]


#165972

FromTomB <tommy.bongaerts@gmail.com>
Date2013-02-22 17:56 +0000
Message-ID<20130222185005.790@usenet.drumscum.be>
In reply to#165938
On 2013-02-22, the following emerged from the brain of Chris Ahlstrom:
>    https://isc.sans.edu/diary/SSHD+rootkit+in+the+wild/15229
>
>    SSHD rootkit in the wild
>    Published: 2013-02-21,
>    Last Updated: 2013-02-22 09:23:59 UTC
>
>    There are a lot of discussions at the moment about a SSHD rootkit
>    hitting mainly RPM based Linux distributions.  Thanks to our
>    reader unSpawn, we received a bunch of samples of the rootkit.
>    The rootkit is actually a trojanized library that links with SSHD
>    and does *a lot* of nasty things to the system.

Just stumbled upon the article though the Linux Advocates G+ group.
Interesting and smart hack. Unfortunately the initial attach vector is
not known yet, but it's clear that root access is required to
compromise a machine (which means it was comprimised anyway).

-- 
Mijnen deem, mijnen deem
Stoeng heelmaal vol exeem
	~ Katastroof

[toc] | [prev] | [next] | [standalone]


#165991

Fromowl <owl@rooftop.invalid>
Date2013-02-22 19:51 +0000
Message-ID<ekyt93.a00t4a@rooftop.invalid>
In reply to#165938
Chris Ahlstrom <OFeem1987@teleworm.us> wrote:
>    https://isc.sans.edu/diary/SSHD+rootkit+in+the+wild/15229

>    SSHD rootkit in the wild
>    Published: 2013-02-21,
>    Last Updated: 2013-02-22 09:23:59 UTC

>    There are a lot of discussions at the moment about a SSHD rootkit
>    hitting mainly RPM based Linux distributions.
>    Thanks to our reader unSpawn, we received a bunch of samples of the
>    rootkit. The rootkit is actually a trojanized library that links with
>    SSHD and does *a lot* of nasty things to the system.

"chrisv" doesn't need to worry about this.

[toc] | [prev] | [standalone]


Page 2 of 2 — ← Prev page 1 [2]

Back to top | Article view | comp.os.linux.advocacy


csiph-web