×
Login Register an account
Top Submissions Explore Upgoat Search Random Subverse Random Post Colorize! Site Rules Donate
25

Criticial library (xz/liblzma) backdoored in Linux, allows remote takeover

submitted by chrimony to whatever 1.1 yearsMar 30, 2024 20:54:04 ago (+25/-0)     (www.bleepingcomputer.com)

https://www.bleepingcomputer.com/news/security/red-hat-warns-of-backdoor-in-xz-tools-used-by-most-linux-distros/

GitHub project was compromised. Mainly a problem if you use a "rolling release" or bleeding edge Linux distro, as the attack occurred in February.

Here's another link with more details: https://lcamtuf.substack.com/p/technologist-vs-spy-the-xz-backdoor


9 comments block


[ - ] dosvydanya_freedomz 6 points 1.1 yearsMar 30, 2024 21:02:15 ago (+6/-0)

linux is the most secure OS ever/s

as long as you have intel or AMD you will always have backdoors at the hardware level

[ - ] oyveyo 5 points 1.1 yearsMar 31, 2024 06:30:47 ago (+5/-0)

Well let me just order an alternative... oh right there are none.

[ - ] dosvydanya_freedomz 1 point 1.1 yearsMar 31, 2024 06:57:35 ago (+1/-0)

oh right there are none.

like i have said backdoors and exploits comes at the hardware lvl

[ - ] chrimony [op] 3 points 1.1 yearsMar 31, 2024 08:43:47 ago (+3/-0)

There's a difference between some state actor being able to hack into your machine versus any script kiddie on the Net.

[ - ] TheNoticing 0 points 1.1 yearsApr 2, 2024 13:26:22 ago (+0/-0)

Yeah, there's unfortunately no alternative to desktop/laptop CPUs. I'd still rather have AMD.

[ - ] deleted 0 points 1.1 yearsMar 31, 2024 06:17:25 ago (+0/-0)

deleted

[ - ] Dingo 6 points 1.1 yearsMar 30, 2024 23:11:05 ago (+6/-0)

It seems to compromise those with glibc userspace with systemd (as vectors) through the process of ssh authentication.

This was exactly the kind of issue linux devs were bitching about when systemd was rolling in. Because systemd touches so many things it can be a malwar or telemetry vector if any other part of the system is compromized.

[ - ] ZyklonDryCleaners 3 points 1.1 yearsMar 31, 2024 07:32:52 ago (+3/-0)

I assume anything with a processor is snitching on me, so I do nothing to conceal my hatred of jews. I spread dissent without a care in the world, because what the fuck is anybody going to do about it?

[ - ] chrimony [op] 4 points 1.1 yearsMar 31, 2024 08:44:33 ago (+4/-0)

It's more about defending yourself from random hackers that want to steal your bank info or use your machine as part of a botnet.

[ - ] TheNoticing 0 points 1.1 yearsApr 2, 2024 13:25:19 ago (+0/-0)

Well shit, that's pretty bad.