TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Compromised EC2 image includes root access SSH key

39 pointsby whiskersabout 14 years ago
A friend just forwarded me this e-mail he received from the Amazon EC2 Security Team.<p>http://pastebin.com/q1VH4rmF<p>Looks like a public Ubuntu EC2 image was available that included an SSH key to allow the publisher to log into any instance that is using this image as root.

3 comments

paulofischabout 14 years ago
Hi there, I originally made this AMI and I would like to apologise to anyone who's instance has been taken offline because they used this image.<p>Through inexperience I left my public SSH key in the AMI, which I failed to appreciate the implications of despite a blog comment highlighting that I'd done so.<p>For the record I'd like to state that I didn't use my unintended powers of root at any point for good or evil.<p>This post stands as a good education of why it's worth checking images of unknown provenance and how to check your public key store for credentials.<p>This issue will mainly affect anyone who wanted an AMI to check out Amazon's free tier which has a 10GB limit on EBS.
评论 #2423001 未加载
评论 #2423055 未加载
评论 #2424821 未加载
评论 #2423105 未加载
snapbuzzabout 14 years ago
Wow! my instance was running this AMI. I am glad that this was not intentional. Kudos to the aws team for looking after it's customers.
NeedLucidAMIabout 14 years ago
paulofisch - are you planning to make a replacement ami that does not include the security hole, for those of use who still want to use ubuntu 10.04 server?
评论 #2426457 未加载