Welcome, Guest. Please login or register.
Did you miss your activation email?
July 31, 2010, 09:11:42 pm

Kubuntu Forums  |  Kubuntu Discussion  |  Previous Kubuntu Releases  |  Kubuntu 8.04 Hardy Heron  |  Software Support  |  Topic: [Closed] Phalanx2 rootkit possibly targeting 2.6.x kernels 0 Members and 1 Guest are viewing this topic. « previous next »
Pages: [1] Go Down Print
Author Topic: [Closed] Phalanx2 rootkit possibly targeting 2.6.x kernels  (Read 889 times)
kjjjjshab
Still Lots to Learn
*****
Offline Offline

Posts: 867


« on: August 27, 2008, 10:46:59 pm »

FYI... I know nothing about it, except for what I read below:

"US-CERT is aware of active attacks against linux-based computing infrastructures using compromised SSH keys. The attack appears to initially use stolen SSH keys to gain access to a system, and then uses local kernel exploits to gain root access. Once root access has been obtained, a rootkit known as "phalanx2" is installed.

Phalanx2 appears to be a derivative of an older rootkit named "phalanx". Phalanx2 and the support scripts within the rootkit, are configured to systematically steal SSH keys from the compromised system. These SSH keys are sent to the attackers, who then use them to try to compromise other sites and other systems of interest at the attacked site.

Detection of phalanx2 as used in this attack may be performed as follows:

    * "ls" does not show a directory "/etc/khubd.p2/", but it can be entered with "cd /etc/khubd.p2".
    * "/dev/shm/" may contain files from the attack.
    * Any directory named "khubd.p2" is hidden from "ls", but may be entered by using "cd".
    * Changes in the configuration of the rootkit might change the attack indicators listed above. Other detection methods may include searching for hidden processes and checking the reference count in "/etc" against the number of directories shown by "ls"..."

US-CERT link

A check of my system was negative.

Edit: Didn't find this with a search earlier, please post here instead:
http://kubuntuforums.net/forums/index.php?topic=3097120.msg144695#msg144695
« Last Edit: August 27, 2008, 11:26:36 pm by kjjjjshab » Logged
Pages: [1] Go Up Print 
Kubuntu Forums  |  Kubuntu Discussion  |  Previous Kubuntu Releases  |  Kubuntu 8.04 Hardy Heron  |  Software Support  |  Topic: [Closed] Phalanx2 rootkit possibly targeting 2.6.x kernels « previous next »
Jump to:  


Powered by MySQL Powered by PHP Powered by SMF 1.1.11 | SMF © 2006-2009, Simple Machines LLC Valid XHTML 1.0! Valid CSS!
Page created in 0.149 seconds with 15 queries.
 

MKPortal M1.1.1 ©2003-2006 mkportal.it
Page generated in 0.03955 seconds with 10 queries