View Issue Details
| ID | Project | Category | View Status | Date Submitted | Last Update |
|---|---|---|---|---|---|
| 0001096 | Kali Linux | Kali Package Bug | public | 2014-03-18 18:36 | 2025-07-14 09:36 |
| Reporter | tottikm | Assigned To | dookie | ||
| Priority | normal | Severity | major | Reproducibility | always |
| Status | closed | Resolution | no change required | ||
| Platform | x64 | OS | Kali | OS Version | 1.0 |
| Product Version | 1.0.6 | ||||
| Summary | 0001096: openssh package infected with backdoor | ||||
| Description | Hi Guys, I was reading this news on the internet, http://thehackernews.com/2014/03/operation-windigo-linux-malware.html, this a backdoor using the openssh package. I made the verification suggested in the article and in the report http://www.welivesecurity.com/wp-content/uploads/2014/03/operation_windigo.pdf, and I was infected. To be sure that I wasn't infected through other vectors I made a fresh install and the results are the same, please check and confirm. I will disable ssh services for now until have an answer. | ||||
| Steps To Reproduce | Execute this little command in terminal, | ||||
|
major thing ... Need to be FIXED ... |
|
|
Sorry to hear you're infected but it's not from Kali: root@kali:~# uname -a root@kali:~# uname -a Make sure you only download Kali Linux from us and always check the SHA sums provided. |
|
| Date Modified | Username | Field | Change |
|---|---|---|---|
| 2014-03-18 18:36 | tottikm | New Issue | |
| 2014-03-18 20:46 | kamtec1 | Note Added: 0001628 | |
| 2014-03-18 21:28 | dookie | Note Added: 0001629 | |
| 2014-03-18 21:28 | dookie | Status | new => closed |
| 2014-03-18 21:28 | dookie | Assigned To | => dookie |
| 2014-03-18 21:28 | dookie | Resolution | open => no change required |
| 2025-07-14 09:36 | g0tmi1k | Priority | high => normal |