SSH "Vulnerabilities"
      by Wyatt WalterI had to laugh when I read the comments on zdnet’s article on how compromised SSH keys are leading to rootkits in Linux systems. Okay, I’ll admit it. I’m a Linux fan and am going to be partial to defending my pet operating system, but let’s all take a minute to think about this. The first part of the attack happens when an attacker is first able to login to an SSH server with a stolen key. Once the attacker has a shell, they are using a vulnerabilities to install rootkits. Sure, that means there are vulnerabilities once a user has a shell, and I’m not about to say that Linux is impenetrable. But let’s consider what’s happening here. The attackers are using a stolen key. The attackers could just as easily use a stolen password. The same would happen if you opened up remote desktop on your Windows server to the world and gave out your password. Okay, so this was mostly a rant about some comments made, but let’s all take the time and watch what public-facing services are running on our systems. Don’t open up a service on your servers if you don’t plan on logging and auditing the service. All OS’s are vulnerable to attacks due to poor implementation and good grief, be careful with your keys!
I also had to laugh when I went to the CERT article that the zdnet article was about. Right below it, CERT issued a warning about a vulnerability in PowerPoint that allowed remote code execution with escalated privileges if a user opened a crafted file. Wow, talk about irony! Yes, I know that there’s vulnerabilities in software from pretty much every vendor so don’t flame me, but I loved the irony.
Related Posts- Ubuntu: So Easy a 10 Year-Old Can Do It Okay, this "Linux is hard" FUD is driving me insane....
- Vista Fans Are Just as Bad as Linux Fans The pattern is as sure as the sun rises: Someone...
- Uptime In Windows One of the many things that has annoyed me about...
- Once Again, Social Engineering Proves Much Easier Than Real Engineering Whatever Twittercut was or wasn't, it does seem to have...
- 5 Dead (But Functional) Trends I Rock Like A Champ On 12/24 we saw some of the male clothing trends...
- Tiger Woods Expects to be an Even Better Golfer Upon His Re-debut in 2009 Anyone who was hoping that Tiger Woods would have lost...
- Why Big Companies Are Blogging? There are still some old school business people out there...
Tags: security, ssh
Filed under Tech Trends :
Comments (0) :
Aug 28th, 2008


