Rocket Software Homepage
Forum Home Forum Home > AccuTerm Knowledge Base (read only) > Connectivity
  New Posts New Posts RSS Feed - Accuterm and Ebury SSH rootkit detection
  FAQ FAQ  Forum Search   Register Register  Login Login

The AccuTerm forum has moved. Go to community.rocketsoftware.com to register for the new Rocket forum.

Forum LockedAccuterm and Ebury SSH rootkit detection

 Post Reply Post Reply
Author
Message
chrismac2 View Drop Down
Newbie
Newbie


Joined: July 07 2014
Location: United States
Status: Offline
Points: 1
Post Options Post Options   Thanks (0) Thanks(0)   Quote chrismac2 Quote  Post ReplyReply Direct Link To This Post Topic: Accuterm and Ebury SSH rootkit detection
    Posted: July 07 2014 at 10:00am
Hello,
 
I am troubleshooting an issue where some users I support who use Accuterm to connect via SSH to a system outside are network, are triggering Symantec Alerts on our firewall for the Ebury SSH Rootkit Command and Control traffic.
 
Are there any other reports for this?   Is it a problem with the SSH built into Accuterm?
Back to Top
PSchellenbach View Drop Down
Admin Group
Admin Group

Moderator

Joined: December 15 2003
Location: United States
Status: Offline
Points: 2150
Post Options Post Options   Thanks (0) Thanks(0)   Quote PSchellenbach Quote  Post ReplyReply Direct Link To This Post Posted: July 09 2014 at 5:27am
Hi Chris -

I don't think AccuTerm can cooperate with the Ebury SSH exploit. Maybe Symantec is catching a false positive. I did a quick search about Ebury SSH and the analysis at this site http://www.welivesecurity.com/2014/02/21/an-in-depth-analysis-of-linuxebury/ indicates that the client needs to send a carefully crafted SSH version string when the connection is set up. The string sent by AccuTerm is
SSH-2.0-atssh.1.3
which is nothing like the version strings noted in the article. But it might not be a string that Synantec recognizes as a valid SSH client.

Thanks,

Pete
Back to Top
 Post Reply Post Reply
  Share Topic   

Forum Jump Forum Permissions View Drop Down

Forum Software by Web Wiz Forums® version 12.03
Copyright ©2001-2019 Web Wiz Ltd.