A lot of talk has been taking place about an underground openssh exploit. It appears to be linked to the following exploit tools:“./0pen0wn” or “./0penPWN” by the hacker group called “anti-sec.”
anti-sec:~/pwn/xpl# ./openPWN -h-p 22 -l=users.txt
[+] openPWN - anti-sec group
[+] Target:
[+] SSH Port: 22
[+] List: users.txt
[~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~>]
and:
anti-sec: ~ / pwn / xpl # ./0pen0wn-h -p 22 [+] 0wn0wn – anti-sec group [+] 0wn0wn - anti-sec group
[+] Target: 66.197.143.133 [+] Target:
[+] SSH Port: 22 [+] SSH Port: 22
[~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~>]
One website reported a log of the attack that can be found here. There is a lot of discussion of whether this is real or not. It is recommended to make sure that your openssh is at the current version, using a secure configuration, and that your are monitoring the activity against your systems until more information is released on this issue.





