quinta-feira, 21 de maio de 2015

Latest Version of SSH Client, "PuTTY", Steals Users Credentials

"PuTTY" Developed by Simon Tatham is a Free and Open Source Terminal Emulator for Windows System, Used to Remote Access with Linux / Unix. It is Used by System Administrators, Database Managers and Web Developers. According to Symantec Researchers, an Unofficial Version of the Open Source SSH Client, "PuTTY", has been Found which May Compromise the Users Privacy.


"If the user is connected to other computers or servers through the malicious version of PuTTY, then they could have inadvertently sent sensitive login credentials to the attackers. Data that is sent through SSH connections may be sensitive and is often considered a gold mine for a malicious actor. Attackers can ultimately use this sensitive information to get the highest level of privileges on a computer or server, (known as “root” access) which can give them complete control over the targeted system."




A Trojanized Version of "PuTTY" is being Hosted on Websites, from the Official Domain and Cyber Attackers Used to Redirect Users to their Own Websites. This Trojanized "PuTTY" Version was 1st Spotted in the Wild Late 2013, in a Limited Number of Detection. To Protect Yourself Becoming a Victim, you Need to Check the Source of your Download. Make Sure you Download the Files from the Official Homepage from the Author or Publisher.



0 comentários:

Enviar um comentário