Putty with malicious code...

Status
Not open for further replies.

cyberjock

Inactive Account
Joined
Mar 25, 2012
Messages
19,525
Here...

http://it.slashdot.org/story/15/05/19/1422241/trojanized-info-stealing-putty-version-lurking-online

One of the best first steps in setting up a Windows machine is to install PuTTY on it, so you have a highly evolved secure shell at your command. An anonymous reader writes, though, with a note of caution if you're installing PuTTY from a source other than the project's own official page.

A malicious version with information-stealing abilities has been found in the wild. According to the article: Compiled from source, this malicious version is apparently capable of stealing the credentials needed to connect to those servers. "Data that is sent through SSH connections may be sensitive and is often considered a gold mine for a malicious actor. Attackers can ultimately use this sensitive information to get the highest level of privileges on a computer or server, (known as 'root' access) which can give them complete control over the targeted system," the researchers explained.

The Symantec report linked above also shows that (at least for this iteration) the malware version is easy to spot, by hitting the "About" information for the app.
 
Joined
Jan 9, 2015
Messages
430
Glad I'm not using Putty/Windows anymore. Thanks @cyberjock.
 

Ericloewe

Server Wrangler
Moderator
Joined
Feb 15, 2014
Messages
20,194
Just goes to show you should always download from an official source.
 

DrKK

FreeNAS Generalissimo
Joined
Oct 15, 2013
Messages
3,630
This has been a thing for 15 years.

At least.

And bitvise is way better than putty on Windows, anyway :)
 

cyberjock

Inactive Account
Joined
Mar 25, 2012
Messages
19,525
This has been a thing for 15 years.

At least.

And bitvise is way better than putty on Windows, anyway :)

Your mom is way better...
 
Status
Not open for further replies.
Top