Hi,
I expect you already heard about the new Chaos malware[1,2], a Go-based malware that can attack multiple architectures and operating systems, including FreeBSD.
To me it's not fully clear how this could affect FreeBSD. And furthermore how to defend against it. Maybe you could help me.
It seems to come via exploitable vulnerabilities (But which? There seem to be
CVE-2017-17215[3], CVE-2022-30525[4] and CVE-2022-1388[5] ... seems not FreeBSD-specific at a first glance), over brute-forced ssh entry-points (also by using stolen ssh keys). Is this the only possible attack-way?
And advises against infections are not special: keep systems up-to-date, use strong passwords, use multi-factor-authentication. But is this all? Can you consider being safe if you follow these advises?
Kind regards,
trutlze
[1] https://arstechnica.com/information...fected-hundreds-of-linux-and-windows-devices/
[2] https://blog.lumen.com/chaos-is-a-go-based-swiss-army-knife-of-malware/
[3] https://nvd.nist.gov/vuln/detail/CVE-2017-17215
[4] https://nvd.nist.gov/vuln/detail/CVE-2022-30525
[5] https://nvd.nist.gov/vuln/detail/CVE-2022-1388
I expect you already heard about the new Chaos malware[1,2], a Go-based malware that can attack multiple architectures and operating systems, including FreeBSD.
To me it's not fully clear how this could affect FreeBSD. And furthermore how to defend against it. Maybe you could help me.
It seems to come via exploitable vulnerabilities (But which? There seem to be
CVE-2017-17215[3], CVE-2022-30525[4] and CVE-2022-1388[5] ... seems not FreeBSD-specific at a first glance), over brute-forced ssh entry-points (also by using stolen ssh keys). Is this the only possible attack-way?
And advises against infections are not special: keep systems up-to-date, use strong passwords, use multi-factor-authentication. But is this all? Can you consider being safe if you follow these advises?
Kind regards,
trutlze
[1] https://arstechnica.com/information...fected-hundreds-of-linux-and-windows-devices/
[2] https://blog.lumen.com/chaos-is-a-go-based-swiss-army-knife-of-malware/
[3] https://nvd.nist.gov/vuln/detail/CVE-2017-17215
[4] https://nvd.nist.gov/vuln/detail/CVE-2022-30525
[5] https://nvd.nist.gov/vuln/detail/CVE-2022-1388