Report of an NSA Employee about a Backdoor in the OpenSSH Daemon (2012) [pdf]
spiegel.de
spiegel.de
Title should be "NSA Employee Reports Developing OpenSSH Rootkit".
This one is just a custom OpenSSH version with a backdoor.
"A rootkit is a stealthy type of software, typically malicious, designed to hide the existence of certain processes or programs from normal methods of detection and enable continued privileged access to a computer"
...continued privileged access. In the *nix world, this is understood to mean root.
These are the primary characteristic of a rootkit. To wit, from that same article:
> Rootkit detection is difficult because a rootkit may be able to subvert the software that is intended to find it. Detection methods include using an alternative and trusted operating system, behavioral-based methods, signature scanning, difference scanning, and memory dump analysis. Removal can be complicated or practically impossible, especially in cases where the rootkit resides in the kernel; reinstallation of the operating system may be the only available solution to the problem.[2] When dealing with firmware rootkits, removal may require hardware replacement, or specialized equipment.
These problems are what rootkits are associated with. The backdoored SSH described in the paper does not qualify. Detecting it is fairly straightforward, and on its own it makes no attempt to hide any programs that it spawns. EDIT: further, as described it makes no efforts to avoid removal.
> enable continued privileged access to a computer
If you strip away the rest of the definition and only look at this part, then by your definition the vanilla SSH server is a rootkit.
Stefan Sperling Sat, 17 Jan 2015 14:44:15 -0800
On Sat, Jan 17, 2015 at 10:59:19PM +0100, Daniel Cegiełka wrote:
> http://www.spiegel.de/media/media-35663.pdf
>
> "PANT SPARTY is a backdoor in the SSH daemon for *NIX, based on
> OpenSSH portable"
They are not talking about the official OpenSSH code.
To save everyone a bit of time (and hassle with a PDF), from the same document:
"It allows a public key to be embedded in the sshd binary and will then always grant a root login shell if presented with the proper key pair for that key. [...] authorized_keys as a quick-and-easy method of persistence [...] obviously isn't very stealthy [...] The goal for this project was to provide the same level of persistence but embedded in the sshd binary itself (obviously, assuming root access, as before)"
In other works, no backdoor in sshd unless the system has already been rooted by other means and sshd replaced with a bugged binary. Boohoo.
[1] http://www.mail-archive.com/misc@openbsd.org/msg135510.html
> New Zealand was incredible! I wish I’d had more time there, but I did pretty well. I saw a handful of LOTR sights, Mount Cook, a number of gorgeous lakes, snow-capped mountains everywhere ... I absolutely loved my time in Australia, both in terms of work and travel, but I’m also looking forward to returning to the land of Chick-fil-A, college athletics, BBQ pork, and real bacon. Oh, and good beer.
It's great that they love their work, but it's too bad so many smart people are going to work on projects that violate so many people's rights.
Don't worry. It's ok because the Good Guys(tm) would never do anything bad. They would make them Bad Guys(tm)!
The sad thing is that a lot of them probably believe they are the good guys, and that they'll be able to clearly tell when they start crossing a line towards The Dark Side. We all live in our own bubbles, after all.
If you've never seen The Boxtrolls, it's a moderately funny newish kids movie, but some of the parts that I enjoyed the most about that movie were the scenes with the two evil henchmen. I enjoyed it because they'd convinced themselves that they were the good guys, fighting the good fight and all that. But as the movie goes on their perspective slowly changes as they become more aware of the impact they're having on the protagonists.
I firmly believe there are very few healthy people out there who honestly want to watch the world burn, we should all be aware of the impact we're having on those around us. It's easy to write off an opposing side as evil do-er, but in all likelihood they see themselves as fighting the good fight just as much as you do.
This exploit is something that needs to be specifically installed by someone - it's not something you'd use to exploit the masses, it's something you'd use to monitor a target further once you already had (perhaps temporary) root access.
In that sense, it's basically just bread-and-butter spy work. It's hard to accept that the government has any reason to monitor the population to the extent that the NSA does - but it would be conversely completely foolish to say that they have no business developing attacks for computers - it would be like saying they have no business developing lock pick tools or electronic bugs.
History has shown that a strong nation has at least some need for intelligence and counter-intelligence, and the US has historically had incredibly poor capabilities for both, which has lead to the deaths of thousands (thinking about Vietnam intelligence specifically).
It thus seems at least foolish to criticise what's clearly an impressive targeted exploit - which to some extent demonstrates the US' dominance in the field.
This isn't something that the public has any business knowing - this is just plain espionage.
Go figure.
Good to know. Time for a security audit of every authorized_keys file I maintain.
Physical access to the target's system.
Control the network upstream of the target so that the modified checksum and package can be delivered during package upgrades.
Compromise the mirror used by the target to provide the modified checksum and package.
Hide the code changes in a series of semi-related ostensibly legitimate pull requests. Legitimise your pull requests by developing corner cases which expose "bugs" in the software you wish to attack.
Crowbar attack against the upstream maintainer.
"USB key in the carpark" attack.
Those are some ideas. I don't claim to be an expert in the area.