Showing posts with label DarkLeech. Show all posts
Showing posts with label DarkLeech. Show all posts

Saturday, January 26, 2013

Hackers placed SSH backdoor on hacked servers


Group of hackers infect web servers fake module for the server Apache, beginning distribute SSH service with built backdoor to steal passwords and administrator on the server.

In the latter case, a group of hackers replace all the binary files associated with the SSH backdoor on the compromised server-version, designed specifically to capture all input via SSH-session data and transfer them to the controlled server side. This was told at Sucuri, dedicated to the protection against web-based attacks.

"I have seen SSHD-backdoors in the past, though in a small scale and not on public servers. However, the new attack is different from anything he had seen before," - says Daniel Cid, CTO Sucuri. Hackers modify not only SSH-demon, but all the SSH-binaries (SSH, SSH-agent and SSHD) with the main goal - to steal credentials from the server.