5 ms·
Spreads via password authenticated SSH, which is the first thing you disable when you set up an SSH server. Doesn't hide its CPU usage. Does a few mildly crafty
by morserer 3y ago
Spreads via password authenticated SSH, which is the first thing you disable when you set up an SSH server. Doesn't hide its CPU usage. Does a few mildly crafty things to prevent reverse engineering, but overall this "worm" just seems like it's picking low-hanging fruit.
This doesn't seem serious at all, nor difficult to detect. Am I missing something?
- themoonisachees 3y agoSame. It has some nicer evasion techniques but nothing out of the ordinary, to me this seems like a guy bought a malware suite that's above his pay grade and sent it off on ssh scans.
- guenthert 3y agoYeah, I was surprised that this is still a thing in 202x, but then, there are many devices out there, which run a ssh server, which one wouldn't have 'installed'. Seems it targets IoT devices. Rather than (intentionally) causing DDoS, it mines cryptocoins (with great patience, I suppose), so it's more like a parasite, siphoning electricity and doing it's part to warm the globe.
- huytersd 3y agoWait, if you disable password authenticated SSH, how do you log into the server?
- jxcl 3y agoPublic key authentication, with your private keys in your .ssh folder and your public key in the server’s .ssh/authorized_keys file
- gumby 3y agoYou can have a password on the client end to unlock access to the keys, if you like. The point of ssh is to use the keys for authentication. Having the ssh server permit password login is a back-compatible legacy from the telnet days and has been functionally obsolete for decades.