Web hosting provider Linode jeopardized the security of its customers’ virtual machines, potentially allowing attackers to hijack the SSH connections initiated by customer system administrators, according to IT watchdog site, The Register.

Linode promotes “High performance SSD Linux servers for all of your infrastructure needs.” Linode’s client list includes numerous, high-profile, cloud-based businesses, many of whom store sensitive customer information on Linode’s servers.

Nodes that were installed with an image of Linode’s Ubuntu 15.10 between November 10, 2015, and February 4, 2016 all use the same SSH server key. Usually, a unique key is generated during installation of a Linux distro, but that doesn’t appear to have happened for months in this case.  As a result, an attacker could use the common server key to set up a man-in-the-middle attack using a malicious server that masquerades as the customer’s  vulnerable virtual machine. If successful, the hacker could quietly intercept login credentials, files, commands, and other data sent by the unknowing administrator and, ultimately, hijack the machine.

