<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>CounterMeasures -  A Security Blog » SSH</title>
	<atom:link href="http://countermeasures.trendmicro.eu/tag/ssh/feed/" rel="self" type="application/rss+xml" />
	<link>http://countermeasures.trendmicro.eu</link>
	<description>Trend Microâ€™s Rik Ferguson blogs about current security issues.</description>
	<lastBuildDate>Wed, 01 Feb 2012 14:48:59 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>Apache SSH Key compromised</title>
		<link>http://countermeasures.trendmicro.eu/apache-ssh-key-compromised/</link>
		<comments>http://countermeasures.trendmicro.eu/apache-ssh-key-compromised/#comments</comments>
		<pubDate>Fri, 28 Aug 2009 11:22:28 +0000</pubDate>
		<dc:creator>Rik Ferguson</dc:creator>
				<category><![CDATA[Site Compromise]]></category>
		<category><![CDATA[compromise]]></category>
		<category><![CDATA[SSH]]></category>
		<category><![CDATA[web]]></category>

		<guid isPermaLink="false">http://countermeasures.trendmicro.eu/?p=1287</guid>
		<description><![CDATA[UPDATE: AÂ post regarding this incident from apache.org is available at https://blogs.apache.org/infra/entry/apache_org_downtime_initial_report ______________________________________________________________________________Â  As of this moment, Apache.org is reporting that SSH key associated with its US servers has been compromised and are shifting all traffic to their European mirror. Â  Details of the attack/compromise are few at the moment, as this is breaking news. It [...]<div class="addthis_toolbox addthis_default_style " addthis:url='http://countermeasures.trendmicro.eu/apache-ssh-key-compromised/' addthis:title='Apache SSH Key compromised '  ><a class="addthis_button_facebook_like" fb:like:layout="button_count"></a><a class="addthis_button_tweet"></a><a class="addthis_button_google_plusone" g:plusone:size="medium"></a><a class="addthis_counter addthis_pill_style"></a></div>]]></description>
			<content:encoded><![CDATA[<p><strong>UPDATE</strong>: AÂ post regarding this incident from apache.org is available at <a href="https://blogs.apache.org/infra/entry/apache_org_downtime_initial_report">https://blogs.apache.org/infra/entry/apache_org_downtime_initial_report</a></p>
<p>______________________________________________________________________________Â </p>
<p>As of this moment, Apache.org is reporting that SSH key associated with its US servers has been compromised and are shifting all traffic to their European mirror.</p>
<p><a href="http://countermeasures.trendmicro.eu/wp-content/uploads/2009/08/28-08-2009-12-10-13.png"><img class="alignleft size-full wp-image-1288" title="28-08-2009 12-10-13" src="http://countermeasures.trendmicro.eu/wp-content/uploads/2009/08/28-08-2009-12-10-13.png" alt="28-08-2009 12-10-13" width="510" height="228" /></a></p>
<p>Â </p>
<p>Details of the attack/compromise are few at the moment, as this is breaking news. It is worth remembering however that a compromised SSH key led to <a title="Linux under attack: Compromised SSH keys lead to rootkit" href="http://blogs.zdnet.com/security/?p=1803" target="_blank">in-the-wild exploitation of Linux based</a>Â systems exactly this time last year, for the purposes of installing rootkits. Keep your eye on how this story develops.</p>
<p>Â </p>
<p>Apache servers account for around 50% of all web servers in the <a title="July 2009 Web Server Survey" href="http://news.netcraft.com/archives/2009/07/28/july_2009_web_server_survey.html" target="_blank">July 2009 web server survey</a>.</p>
<div class="addthis_toolbox addthis_default_style " addthis:url='http://countermeasures.trendmicro.eu/apache-ssh-key-compromised/' addthis:title='Apache SSH Key compromised '  ><a class="addthis_button_facebook_like" fb:like:layout="button_count"></a><a class="addthis_button_tweet"></a><a class="addthis_button_google_plusone" g:plusone:size="medium"></a><a class="addthis_counter addthis_pill_style"></a></div>]]></content:encoded>
			<wfw:commentRss>http://countermeasures.trendmicro.eu/apache-ssh-key-compromised/feed/</wfw:commentRss>
		<slash:comments>6</slash:comments>
		</item>
	</channel>
</rss>

