1 min read
SSH Lateral Movement on Linux: Risks and How to Stop It
27February 2025
1 min read
Sandfly Security - Agentless Linux EDR and Incident Response Updated on September 29, 2026
03 March 2025
Linux systems face growing threats, making password security critical. Our white paper and video below on Linux password hashes exposes the risks of outdated hashing algorithms and provides practical solutions:
White Paper: Linux Password Hash Risks
Over the years, password hashes on Linux have been updated to stay ahead of advances in hardware brute force attacks. However, Linux systems often use legacy hashes with poor passwords making credential theft a significant risk. In the paper and video above we go over the range of hashes available to protect Linux today and rate them as follows:
Strong hashes alone aren’t enough—passwords must be robust. Our white paper advises a minimum of 15 characters, but passphrases (e.g., seven-word Diceware-generated strings) are ideal. They’re both highly secure and easier to remember than complex passwords.
Even with solid hashing, a breached system lets attackers grab passwords in plaintext though sniffing and other attacks. Sandfly suggests moving beyond passwords entirely, but since they’re still common, combining strong passwords with modern hashes is vital. Additionally, embedded devices often rely on weak default passwords and outdated hashes, making them prime targets. Sandfly’s agentless security tools can spot these vulnerabilities, securing systems that are often ignored.
Sandfly can help find obsolete password hashes and audit systems for weak passwords that can lead to immediate compromise. Please see the white paper above, and our white paper on agentless password auditing, to see how Sandfly can protect systems agentlessly against these threats.
Post Tags:
Share this post:
1 min read
27February 2025
1 min read
Publication Date: 13 February 2025
1 min read
Publication Date: 02 December 2024