IT Safety News - Your source for network security news, opinion, product comparisons and reviews. Virus, Worms, Antivirus and Security Information.
Showing posts with label attacks Linux-servers. Show all posts
Showing posts with label attacks Linux-servers. Show all posts
Friday, February 22, 2013
Malicious code Sshdkit attacks Linux-servers
In the anti-virus company 'Doctor Web' today told about new to the unusual Linux-vredonosa, hacking web servers. The harmful Linux.Sshdkit program represents dynamic library, thus there are its versions both for 32-bit, and for 64-digit versions of distribution kits of Linux.
Trojan propagation mechanism is still not fully understood, but there are reasons to believe that this installation to a server by using a critical vulnerability. Last known specialists "Doctor Web" version of the malware has number 1.2.1, and one of the earliest - 1.0.3 - apply for a fairly long time.
After a successful installation in the Trojan embedded in the process sshd, intercepting the authentication function of the process. After installing the session and successfully entering the user name and password are sent to the remote server to the attacker through a protocol UDP. IP-address of the control center, "sewn up" in the body of the Trojan, but the server address command every two days regenerated. For this Linux.Sshdkit uses a peculiar algorithm for selecting the team name server.
Subscribe to:
Posts (Atom)
