- http://d.hatena.ne.jp/AO533/20140322/p1:Linux/BSDサーバ2万5千台超がOperation Windigo汚染
- http://www.symantec.com/connect/blogs/25000-linuxunix-operation-windigo:25,000 台もの Linux/UNIX サーバーに侵入した Operation Windigo
元になってるWe Live Securityの記事(PDF)
We will provide two means of identifying the presence of the OpenSSH backdoor. A quick one that relies on the presence of a feature added by the malware to the ssh binary and a longer one which requires inspection of the shared memory segments used by the malware.
The command ssh -G has a different behavior on a system with Linux/Ebury.A clean server will print
ssh: illegal option -- Gto stderr but an infected server will only print the usage.
ということでチェックするにはssh -Gの結果を見ること。
ssh -G 2>&1 | grep -e illegal -e unknown > /dev/null && echo “System clean” || echo “System infected”