▲ 520 ▼ backdoor in upstream xz/liblzma leading to ssh server compromise (www.openwall.com) submitted 2 years ago by Atemu@lemmy.ml to c/linux@lemmy.ml 96 comments fedilink hide all child comments
[–] umami_wasbi@lemmy.ml 11 points 2 years ago (1 child) It seems like a RCE, rather an auth bypass once though. https://bsky.app/profile/filippo.abyssdomain.expert/post/3kowjkx2njy2b permalink fedilink source hideshow 2 child comments replies: [–] tal@lemmy.today 3 points 2 years ago* Apparently the backdoor reverts back to regular operation if the payload is malformed or the signature from the attacker's key doesn't verify. Unfortunately, this means that unless a bug is found, we can't write a reliable/reusable over-the-network scanner. Maybe not. But it does mean that you can write a crawler that slams the door shut for the attacker on any vulnerable systems. EDIT: Oh, maybe he just means that it reverts for that single invocation. permalink fedilink source parent
[–] tal@lemmy.today 3 points 2 years ago* Apparently the backdoor reverts back to regular operation if the payload is malformed or the signature from the attacker's key doesn't verify. Unfortunately, this means that unless a bug is found, we can't write a reliable/reusable over-the-network scanner. Maybe not. But it does mean that you can write a crawler that slams the door shut for the attacker on any vulnerable systems. EDIT: Oh, maybe he just means that it reverts for that single invocation. permalink fedilink source parent