this post was submitted on 29 Mar 2024
79 points (98.8% liked)

Cybersecurity

5388 readers
104 users here now

c/cybersecurity is a community centered on the cybersecurity and information security profession. You can come here to discuss news, post something interesting, or just chat with others.

THE RULES

Instance Rules

Community Rules

If you ask someone to hack your "friends" socials you're just going to get banned so don't do that.

Learn about hacking

Hack the Box

Try Hack Me

Pico Capture the flag

Other security-related communities !databreaches@lemmy.zip !netsec@lemmy.world !cybersecurity@lemmy.capebreton.social !securitynews@infosec.pub !netsec@links.hackliberty.org !cybersecurity@infosec.pub !pulse_of_truth@infosec.pub

Notable mention to !cybersecuritymemes@lemmy.world

founded 1 year ago
MODERATORS
 

Malicious code planted in xz Utils has been circulating for more than a month.

top 1 comments
sorted by: hot top controversial new old
[–] autotldr@lemmings.world 5 points 5 months ago

This is the best summary I could come up with:


Researchers have found a malicious backdoor in a compression tool that made its way into widely used Linux distributions, including those from Red Hat and Debian.

An update the following day included a malicious install script that injected itself into functions used by sshd, the binary file that makes SSH work.

So-called GIT code available in repositories aren’t affected, although they do contain second-stage artifacts allowing the injection during the build time.

In the event the obfuscated code introduced on February 23 is present, the artifacts in the GIT version allow the backdoor to operate.

“This could break build scripts and test pipelines that expect specific output from Valgrind in order to pass,” the person warned, from an account that was created the same day.

The malicious versions, researchers said, intentionally interfere with authentication performed by SSH, a commonly used protocol for connecting remotely to systems.


The original article contains 810 words, the summary contains 146 words. Saved 82%. I'm a bot and I'm open source!