Feeds

OpenSSH trojaned!

The SSH hits the fan...

  • alert
  • submit to reddit

Choosing a cloud hosting partner with confidence

Copies of OpenSSH packages on popular download sites have been trojaned, developers have warned.

Overnight it was realised that the tarball for OpenSSH 3.4p1 on the
main openBSD (ftp.openbsd.org) mirror was compromised, after developers noticed that the checksum of the package had changed. Other mirror sites might also be affected.

The malicious code is not particularly sophisticated but it is a remotely controllable program that could give potential attackers root access to victim's machines. The backdoor is in the makefile that comes with the package, not the OpenSSH software itself.

Initial analysis suggests that code has been added to the package which generates a shell script which, when compiled, tries to contact 203.62.158.32 (web.snsonline.net) on port 6667. It seems that the trojan is executed during build only.

Who compromised the openSSH package and their motives remain unclear.

OpenBSD developers have been informed on the issue, and a clean-up operation can be expected to commence shortly. For now, however, users would do well to exercise extreme caution in updating their machines.

OpenSSH is a free version of the SSH (Secure Shell) communications suite and is used as a secure replacement for protocols such as Telnet, Rlogin, Rsh, and Ftp. ®

External Links

Copy of Weblog by Australian developer Edwin Groothuis analysing the problem
Other developers sound the alarm bells

Choosing a cloud hosting partner with confidence

Whitepapers

Go beyond APM with real-time IT operations analytics
How IT operations teams can harness the wealth of wire data already flowing through their environment for real-time operational intelligence.
Why CIOs should rethink endpoint data protection in the age of mobility
Assessing trends in data protection, specifically with respect to mobile devices, BYOD, and remote employees.
A strategic approach to identity relationship management
ForgeRock commissioned Forrester to evaluate companies’ IAM practices and requirements when it comes to customer-facing scenarios versus employee-facing ones.
Reg Reader Research: SaaS based Email and Office Productivity Tools
Read this Reg reader report which provides advice and guidance for SMBs towards the use of SaaS based email and Office productivity tools.
Protecting against web application threats using SSL
SSL encryption can protect server‐to‐server communications, client devices, cloud resources, and other endpoints in order to help prevent the risk of data loss and losing customer trust.