Showing posts with label SSH. Show all posts
Showing posts with label SSH. Show all posts

Wednesday, 20 May 2015

Infected Version Of PuTTY Steals Passwords


Cyber criminals are spreading on the Internet an infectious variant of the popular SSH client PuTTY, which is designed to steal passwords. PuTTY is a free open source terminal emulator application as a client for SSH, Telnet, rlogin, and raw TCP protocols can serve.

The now discovered version is not on the official PuTTY download site spreads, but via a hacked another page. The infected version would have been the end of 2013 and then already been distributed over the Internet. Recently, anti-virus company Symantec observed more infections. The infection starts with a user searching through a search engine to PuTTY.

Instead of choosing the official website, the user selects a hacked website. The hacked website sends the user several times and let him finally downloading an infected version. When the user logs in via the infected version on a system, the login information can be sent to the attacker. Users also are advised to check that they only download software from the official website of the supplier or developer.

Tuesday, 12 May 2015

Large DDoS Botnet Of Tens Of Thousands Of Routers Discovered


Researchers have discovered a worldwide botnet consisting of tens of thousands of hijacked routers and is used to carry out DDoS attacks on websites. Reported security Incapsula in a new report . Although the hijacked routers were found in 109 different countries, found that a majority (85%) is located in Brazil and Thailand.

The routers are in turn controlled via servers which are in China and the United States. The researchers thought initially that the routers were acquired via a vulnerability in the firmware. Further investigation showed, however, that all devices were accessible through the standard ports HTTP and SSH. Was not changed in almost all cases the default password.

Thus, the attackers were able to install the "MrBlack" malware on the routers. In addition, a script on the hijacked routers installed it looked for other vulnerable routers. To avoid getting users advised to change the default password such attacks, install the latest firmware and ensure that the operator interface is not accessible via HTTP or SSH. Something that through this tool can be controlled.

Monday, 30 March 2015

43-Year-Old Telnet Still Popular On The Internet


It is 43 years ago this week that Jon Postel RFC 318 published a document in which he described a standard method to control terminal devices at one location from another location, now better known as Telnet (Teletype NETwork). Despite its age and the security problems that are associated with Telnet network protocol is still very popular on the Internet.

John Matherly, the developer of the search engine Shodan, collected in March sorts of information services on the Internet and discovered that Telnet on the sixth place of most state services found behind HTTP, CWMP, SIP, SSH and HTTPS. According Matherly, Telnet is still used by companies and manufacturers. Among other kinds of " smart "products. "The fact that Telnet is easy to use, easy to integrate and requested by users allows Telnet remains popular on the Internet," said Matherly.

Telnet was designed at a time when security hardly played a role and therefore does not have encryption. Besides all kinds of old legacy devices that still use telnet and replaced by SSH is unclear how often the protocol for new products at selected points Matherly. "But the fact remains that even for new programs and devices, and engineers Telnet preferable alternatives."Something Shodan developer both from a security and usability point of view is unwise. Recently reported that the Internet giant Akamai even in the fourth quarter of 2014 as much as 32% of all the observed attack traffic against Telnet was addressed.

Wednesday, 7 January 2015

ISC: Another Port For SSH Is Not Meaningless



Who SSH (Secure Shell) to log on to remote computers and servers will benefit from it to change the default port 22, as late as a handler of the Internet Storm Center (ISC) know. SSH is a popular protocol for managing computers. Standard protocol listens on port 22.

This will also be a lot of scans and attacks on this port. At present, there Reddit , in response to this article , a discussion or change the default port is wise. One of the criticisms is that " security through obscurity "is not a security measure, but only one way to slow an attacker and therefore offers little value. "While it is true that it is difficult to stop a determined attacker to cause you provide, any measure that prevents arbitrary script kiddies and scanners to your SSH look not entirely meaningless," says ISC handler Rick Wanner.

Wanner says more than 15 years SSH on a non-standard port to run, such as port 52222. "Of course this is not the only security measure that I use. I patch daily use hosts.allow where possible, keys and passphrases instead passwords and use Deny Hosts ", he tells. ISC handler notes that he does not use port 22 because of "security through obscurity" benefits, but because it eliminates all noise on port 22.

Port 22 is a favorite target of brute force attacks and port scans rising every year. These activities cause Wanner as much noise in the logs. "Why would you tolerate it if it is not needed?", He notes. The default port change he would attack traffic are much diminished that he occasionally his defense test to see if it still works.