×
Login Register an account
Top Submissions Explore Upgoat Search Random Subverse Random Post Colorize! Site Rules
25

Criticial library (xz/liblzma) backdoored in Linux, allows remote takeover

submitted by chrimony to whatever 1 monthMar 30, 2024 20:54:04 ago (+25/-0)     (www.bleepingcomputer.com)

https://www.bleepingcomputer.com/news/security/red-hat-warns-of-backdoor-in-xz-tools-used-by-most-linux-distros/

GitHub project was compromised. Mainly a problem if you use a "rolling release" or bleeding edge Linux distro, as the attack occurred in February.

Here's another link with more details: https://lcamtuf.substack.com/p/technologist-vs-spy-the-xz-backdoor


10 comments block


[ - ] Dingo 6 points 1 monthMar 30, 2024 23:11:05 ago (+6/-0)

It seems to compromise those with glibc userspace with systemd (as vectors) through the process of ssh authentication.

This was exactly the kind of issue linux devs were bitching about when systemd was rolling in. Because systemd touches so many things it can be a malwar or telemetry vector if any other part of the system is compromized.

[ - ] dosvydanya_freedomz 6 points 1 monthMar 30, 2024 21:02:15 ago (+6/-0)

linux is the most secure OS ever/s

as long as you have intel or AMD you will always have backdoors at the hardware level

[ - ] oyveyo 5 points 1 monthMar 31, 2024 06:30:47 ago (+5/-0)

Well let me just order an alternative... oh right there are none.

[ - ] dosvydanya_freedomz 1 point 1 monthMar 31, 2024 06:57:35 ago (+1/-0)

oh right there are none.

like i have said backdoors and exploits comes at the hardware lvl

[ - ] chrimony [op] 3 points 1 monthMar 31, 2024 08:43:47 ago (+3/-0)

There's a difference between some state actor being able to hack into your machine versus any script kiddie on the Net.

[ - ] TheNoticing 0 points 1 monthApr 2, 2024 13:26:22 ago (+0/-0)

Yeah, there's unfortunately no alternative to desktop/laptop CPUs. I'd still rather have AMD.

[ - ] deleted 0 points 1 monthMar 31, 2024 06:17:25 ago (+0/-0)

deleted

[ - ] TheNoticing 0 points 1 monthApr 2, 2024 13:25:19 ago (+0/-0)

Well shit, that's pretty bad.

[ - ] ZyklonDryCleaners 3 points 1 monthMar 31, 2024 07:32:52 ago (+3/-0)

I assume anything with a processor is snitching on me, so I do nothing to conceal my hatred of jews. I spread dissent without a care in the world, because what the fuck is anybody going to do about it?

[ - ] chrimony [op] 4 points 1 monthMar 31, 2024 08:44:33 ago (+4/-0)

It's more about defending yourself from random hackers that want to steal your bank info or use your machine as part of a botnet.

[ - ] Cantaloupe 2 points 1 monthMar 31, 2024 01:36:01 ago (+2/-0)

Good article