#ssh

41 posts · Last used 3d

Back to Timeline
Peter N. M. Hansteen @pitrh@mastodon.social · 3d ago
0
0
0
Hab da mal was gebastelt... man hat am Wochenende ja nichts Besseres zu tun: Secure Your ServerZwei praktische Checks. Ein seriöser Sicherheitsbericht. Prüfe eine Domain auf die Härtungsdetails, auf die Angreifer und Audits zuerst schauen. Teste danach, ob deine echten E-Mails sauber authentifiziert und zugestellt werden. Kein Konto, kein Tracking, keine Bezahlschranke. Domain-Sicherheitsscan Vollständige externe Sicht auf TLS/SSL, SSH, offene Ports, DNS, SPF, DKIM, DMARC, MTA-STS, HTTP-Security-Header, WHOIS und PGP/WKD. Mail-Zustellungstest Erzeuge eine einmalige Testadresse, schick eine Mail aus deinem Postfach und sieh SPF, DKIM, DMARC, TLS, rDNS, Spam-Signale und Zustellungsdetails. Bugs, Verbesserungswünsche bitte an "hallo [at] chrislo.de" Mehr Infos: https://www.sichere-deinen-server.de/ #chrislo #sys #secureyourserver #sicheredeinenserver #sicherheit #security #server #domain #tls #ssh
0
0
0
Airports Bot @airports_bot@mastodon.world · Aug 06, 2026
0
0
8
Self-Hosted Feed @selfhosted_bot@fd.mrmave.work · Aug 06, 2026
🔓 VoltiusApp/voltius Provides a secure local SSH and SFTP client with zero-knowledge encryption and end-to-end synchronization. Built with Rust and Tauri. ⭐ Stars: 470 📅 Last Update: Aug 05, 2026 https://github.com/VoltiusApp/voltius #selfhosted #homelab #selfhost #selfhosting #opensource #ssh #encryption
0
0
0
heise Security @heisec@social.heise.de · Aug 03, 2026
Neue Malware-Welle: Arch Linux blockiert AUR-Updates Erneut verbreitet sich Malware über Arch User Repositorys. Daher gibt es vorerst überhaupt keine Updates für AUR. https://www.heise.de/news/Neue-Malware-Welle-Arch-Linux-blockiert-AUR-Updates-11395880.html?wt_mc=sm.red.ho.mastodon.mastodon.md_beitraege.md_beitraege&utm_source=mastodon #ArchLinux #IT #Malware #Security #SSH #Tor #Trojaner #news
8
1
8
WinterGate Intelligence Collective👤 @WinterGateIC@infosec.exchange · Aug 03, 2026

INFOSEC EXCHANGE – THREAT INTELLIGENCE BULLETIN

ATTRIBUTION: OUTLAW HACKING GROUP (aka DOTA / SHELLBOT) – CONFIRMED ATTACKER AGAINST WINTERGATE IC INFRASTRUCTURE

CLASSIFICATION: PUBLIC INTELLIGENCE DATE: AUGUST 3, 2026 PREPARED BY: WINTERGATE INTELLIGENCE COLLECTIVE (WIC) CONFIDENCE LEVEL: 98%

EXECUTIVE SUMMARY

After sustained multi-vector attacks against WinterGate IC infrastructure, we have successfully identified the primary threat actor responsible. The attacker is the Outlaw Hacking Group (also tracked as Dota, Shellbot), operating the "mdrfckr" SSH brute-force and cryptomining botnet. This group has been active since at least 2018 and has been observed launching over 46 million sessions from more than 270,000 unique IP addresses.

ATTRIBUTION EVIDENCE

  1. The "mdrfckr" Persistence Key The mdrfckr string is the definitive signature of the Outlaw / Dota family. This persistence key was first associated with the group by Trend Micro in 2018, with subsequent reporting from Anomali, Yoroi, Juniper, CounterCraft, Cybereason, and Kaspersky. Our logs captured the exact mdrfckr signature pattern, confirming the attacker's identity.

  2. Updated SSH Client Libraries (April 2026) Between 14 and 21 April 2026, the mdrfckr campaign was observed using a third libssh client version that had not been previously published as part of this campaign's HASCH chronology. This indicates the group is actively updating its tooling and remains operationally active. Our logs match this updated client fingerprint.

  3. Hydrochasma Fast Reverse Proxy (FRP) Payload The specific payload signature 16030100ee010000ea0303 is a known indicator for the Hydrochasma Fast Reverse Proxy (FRP) tool. Hydrochasma is a previously unidentified threat actor that deploys FRP for persistent, stealthy access, privilege escalation, and lateral movement. The presence of this signature in our logs strongly correlates the scanning activity with this advanced toolset.

  4. Weak SSH Key Exchange Algorithm The use of diffie-hellman-group1-sha1 is a deliberate tactic by the Outlaw group to identify vulnerable, unpatched SSH servers. This deprecated algorithm is a known red flag used by the group to find systems with weak or default credentials.

ATTACK STATISTICS

Total Killed: 19,436 attackers neutralized Blacklisted: 13,106 ipset entries Obliterated: 6,330 attackers neutralized Countermeasures Landed: 1,006,925 RST Injections: 596,348 connection resets State Exhaustion: 27,347 TCP state floods Range Burns: 213 CIDR blocks Deep Penetration Events (L30+): 133,214 Deepest Layer Reached: L70 Final Apex (blocked) Current Live Load: 14.40 Tbps Peak Load: 1.88 Tbps Total Volume Absorbed: 72.88 Tbps

DEFENSE EFFECTIVENESS

All 70+ defensive layers are firing at 100% effectiveness. Conn Ghosting (L34): 80,560 successes Legal Notice Injection (L32): 78,402 successes Full Spectrum Dampen (L39): 59,000 successes Ghost Harassment (L31): 45,153 successes Reverse Amplifier (L21): 40,722 successes Oblivion Engine (L51): 24,848 successes Final Apex (L70): 227 successes

Zero compromises. Zero downtime. Zero data loss.

MODUS OPERANDI

The Outlaw group follows a highly automated and efficient playbook:

  1. Scan: Automated tools scan the internet for servers listening on port 22 (SSH).
  2. Attempt: They try to log in using lists of common or weak usernames and passwords.
  3. Breach: Upon successful login, they immediately install a persistent SSH key (mdrfckr) and change the root password to lock out the legitimate owner.
  4. Payload: They use rsync to load malicious files and modify crontab to ensure persistence across reboots.
  5. Objective: Deploy cryptocurrency mining malware, typically Monero (XMR), and use the compromised system as part of their botnet for further scanning and attacks.

INTELLIGENCE SUMMARY

This is not a targeted attack against WinterGate IC. We are simply one of millions of IP addresses in their scanning range. However, we are the only ones who have successfully identified, tracked, and documented this adversary in real-time. Our infrastructure has absorbed and neutralized every single attempt.

The Outlaw group remains a persistent global threat. In June 2026, they were identified as one of the two most active SSH brute-force groups on cloud platforms, alongside OCNET. Their continued evolution of tooling and tactics confirms they are a well-resourced, enduring adversary.

CALL TO ACTION

  • Network administrators should block all known Outlaw C2 and scanning IPs.
  • Disable weak SSH algorithms such as diffie-hellman-group1-sha1.
  • Enforce strong password policies and key-based authentication.
  • Monitor for the mdrfckr persistence key in authorized_keys files.
  • Review logs for the Hydrochasma FRP payload signature.
  • Implement fail2ban or CrowdSec with custom rules for SSH brute-force protection.
  • Reference BLACKSHIELD threat intelligence for additional IOCs.

The ghost is hunting. The attackers are dying. They don't even know what hit them.

WHAT A FREEZE. ❄️

#Outlaw #mdrfckr #ThreatIntel #SSH #Botnet

0
0
0
BLACKVOID ⚫️ @blackvoid@mastodon.social · Jul 28, 2026
#Synology #DataProtection #APM tip Connecting to the #DP device via #SSH in case you need it goes via port 57. ssh -oKexAlgorithms=diffie-hellman-group1-sha1 -oHostKeyAlgorithms=ssh-rsa -oCiphers=aes128-cbc adminaccount@DP_MGM_IP_ADDRESS -p 57 Once logged in, it will present you with the following actions. #selfhosting #selfhosted #homelab
2
0
2
Daily CyberSecurity @DailyCyberSecurity@infosec.exchange · Jul 28, 2026
Four libssh2 vulnerabilities let a malicious SSH server corrupt memory in connecting clients. Update past version 1.11.1 to stay protected. #libssh2 #SSH #SFTP #Vulnerability #HeapOverflow #CVE #InfoSec #CyberSecurity http://securityonline.info/libssh2-vulnerabilities/?utm_source=mastodon&utm_medium=jetpack_social
0
0
0
Peter N. M. Hansteen @pitrh@mastodon.social · Jul 27, 2026
I wonder if this actually worked somewhere, somewhen, for somebot Jul 27 07:40:21 skapet sshd-session[71062]: Failed password for invalid user root/bin from 217.156.66.34 port 47552 ssh2 #passwordgropers #passwordguessers #sshgropers #ssh #cybercrime #morons #idiots #bots
3
1
2
sudonem @sudonem@infosec.exchange · Jul 26, 2026
RE: https://mastodon.social/@campuscodi/116985884020420822 Like all engineers I deal with imposter syndrome on occasion… and then I get subtle reminders I’m doing better than I thought. #cve #sysadmin #root #linux #infosec #ssh #devops #PlatformEngineering #ImposterSyndrome
Quoting
Catalin Cimpanu @campuscodi@mastodon.social
XCharge EV charging stations can be hacked via the charging port because the connector apparently runs SSH with root/root as the default creds https://www.saiflow.com/blog/the-hidden-ccs2-attack-surface-on-ev-chargers
Open quoted post
9
2
7
Kuketz-Blog 🛡 @kuketzblog@social.tchncs.de · Jul 22, 2026
Gerade den Nitrokey 3A Mini gekauft. Er ersetzt künftig meinen alten Nitrokey Storage und dient mir für OpenPGP bei E-Mails, die SSH-Anmeldung per Public Key sowie die Smartcard-Anmeldung unter Linux. Den verschlüsselten Massenspeicher brauche ich nicht mehr - dafür ist der neue Nitrokey deutlich kleiner und kann dauerhaft am Notebook bleiben. #Nitrokey #OpenPGP #SSH #Linux
0
2
0
Hugo | DevOps | Cybersecurity @hugovalters@mastodon.social · Jul 21, 2026

Stop guessing ciphers. Isolate SSH traffic with ssh, then add ssh.encryption_algorithms as a column to see the exact negotiated cipher. Wireshark parses SSH_MSG_KEXINIT to reveal your key exchange. Audit with confidence.

#wireshark #ssh #cipheraudit

https://www.valtersit.com/vault/wireshark-display-filter-for-ssh-protocol-and-cipher-detecti-fe8312/

2
0
0
Santiago 🔭🪐 @santiago@mastodon.uy · Jun 08, 2026
BREAKING: Bueno, tenemos el agrado de anunciar oficialmente la inauguración de la comunidad Tilde Undernet, para poner en alto los servicios de texto plano, para los amantes del minimalismo y la línea de comandos. Estamos en etapa de pruebas, los registros son solo por recomendación de un usuario existente y son aprobados manualmente y la vía de contacto figura en la capsula gemini de la comunidad. Disponemos de capsulas gemini para usuarios, servidor de noticias NNTP/Usenet, IRC, Telnet BBS, clientes XMPP, lectores de noticias RSS y mucho más. Tenemos una landing page en gemini://undernet.uy #gemini #textoplano #tilde #comunidad #commandline #cli #consola #terminal #ssh #telnet #pubnix #undernet #uruguay #nntp #usenet #capsule
35
1
25
Jesus Michał von Gentoo 🏔 (he) @mgorny@social.treehouse.systems · Jul 21, 2026

I don't know what's more stupid: #OpenSSH using different authentication flow depending on whether you have a .pub file in addition to the private key or not, or #GitHub suddenly starting to reject one of the two valid RFC 4252 workflows.

https://thorsell.io/2026/07/21/github-ssh-keys.html

#SSH

28
7
31
Fabio Manganiello @fabio@manganiello.eu · Jul 15, 2026
@njalla@njalla.social are you aware of any #SSH crawlers lurking for public IPs on your #VPN? Because I’ve noticed a lot of suspicious lines in my system logs when I connect from my laptop to your VPN. Clues: No other system in my networks experiences such SSH scans (and my laptop is the only one that runs Njalla VPN).My laptop has no publicly exposed IP that could justify its SSH port to be reachable from the outside - only the Njalla VPN interface.When I take Njalla down, the scans also stop. Could you please take a closer look at your infra and check that enumeration of connected clients for unauthorized actors is not allowed, or that at the very least such abuses are treated appropriately?
0
0
0