FutureQuest, Inc. FutureQuest, Inc. FutureQuest, Inc.

FutureQuest, Inc.
Go Back   FutureQuest Community > General Site Owner Support (All may read/respond) > Open Discussions
User Name
Password  Lost PW

Reply
 
Thread Tools Search this Thread Display Modes
Old 02-21-2013, 11:04 AM   Postid: 182386
SneakyDave
Registered User

Forum Notability:
93 pts: Helpful Contributor
[Post Feedback]
 
Join Date: Feb 1999
Posts: 953
Interesting SSHD Exploit

For those running their own servers. Appears to possibly be related to a keylogger installed via the java exploit bug.

Look for the existence of a /lib64/libkeyutils.so.1.9 (64 bit) or /lib/libkeyutils.so.1.9 (32 bit) file, and if you have it, you're probably infected.

Script to check for the vulnerability... (be careful not to run unknown scripts as root though!)

http://www.cloudlinux.com/blog/clnews/sshd-exploit.php

More discussion...
http://www.webhostingtalk.com/showthread.php?t=1235797

Last edited by SneakyDave : 02-21-2013 at 02:00 PM. Reason: Added a caution about running unknown scrript via wget.
SneakyDave is offline   Reply With Quote
Old 02-21-2013, 12:16 PM   Postid: 182387
 Kevin
Systems Administrator
 
Kevin's Avatar
 
Join Date: Aug 2001
Location: Orlando, FL
Posts: 2,986
Re: Interesting SSHD Exploit

I had heard of this problem but I hadn't seen that cloudlinux.com link yet.

I got a good laugh at the idea of running:
Code:
wget -qq -O - http://www.cloudlinux.com/sshd-hack/check.sh |/bin/bash
to determine if you have been infected. That sounds like a really good way to get infected with something to me

But I was curious so I did it without the |bash part which means I just got their script dumped to my screen without it doing anything. Then I got another laugh that their script considered infection found to be a success and infection not found to be a failure.
__________________
Kevin
Kevin is offline   Reply With Quote
Old 02-21-2013, 01:57 PM   Postid: 182388
SneakyDave
Registered User

Forum Notability:
93 pts: Helpful Contributor
[Post Feedback]
 
Join Date: Feb 1999
Posts: 953
Re: Interesting SSHD Exploit

Right, I thought the same thing. Their description was informative, but I wouldn't just go running a wget to execute an unknown script as root
SneakyDave is offline   Reply With Quote
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 visitors)
 

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 12:30 AM.


Running on vBulletin®
Copyright © 2000 - 2019, Jelsoft Enterprises Ltd.
Hosted & Administrated by FutureQuest, Inc.
Images & content copyright © 1998-2019 FutureQuest, Inc.
FutureQuest, Inc.