Skip to main content

Hackers Put A Price Tag On New Attack Tool - Want it ? It will cost you !

posted onOctober 19, 2001
by hitbsecnews

A new hacking tool is being actively used by attackers hoping to take remote control of unpatched Unix-based systems, security experts warned today. While the attack tools exploit a relatively old bug for which patches were issued months ago, Temmingh reports that one individual was asking for unspecified financial compensation for sharing the script - a development which he views as ominous.

The tool appears to exploit a known bug in a popular authentication technology called Secure Shell (SSH), according to Simple Nomad, senior security analyst with Bindview Corporation. The security firm's RAZOR team, a research and development group, discovered the flaw in the SSH daemon, which it dubbed the crc32 vulnerability, last winter....

Hackers Put A Price Tag On New Attack Tool

By Brian McWilliams, Newsbytes

In its February advisory, Bindview stated that it was aware of no working exploits for the overflow flaw in the SSH daemon. But last week, rumors spread in the hacker underground that scripts were available to gain "root" or system-level access to vulnerable systems. And in recent days, system operators have posted reports on security mailing lists saying they are receiving remote scans from attackers attempting to locate vulnerable systems running SSH.

According to Roelof Temmingh, technical director for SensePost, an information security consulting firm, several versions of the SSH attack scripts have been available over Internet relay chat and other online forums for approximately one week.

Click here to continue reading this article at NewsBytes.com

Source

Tags

Networking

You May Also Like

Recent News

Tuesday, July 9th

Wednesday, July 3rd

Friday, June 28th

Thursday, June 27th

Thursday, June 13th

Wednesday, June 12th

Tuesday, June 11th

Friday, June 7th

Thursday, June 6th

Wednesday, June 5th