Unable to load image

Nasty exploit in xz/liblzma - :marseyjewoftheorientglow: developer of two years snuck an exploit into *upstream* allowing passwordless sshd compromises. :marseyworried:

https://www.openwall.com/lists/oss-security/2024/03/29/4

Follower of Christ :marseyandjesus: Tech lover, IT Admin, heckin pupper lover and occasionally troll. I hold back feelings or opinions, right or wrong because I dislike conflict.

35
Jump in the discussion.

No email address required.

HN: https://news.ycombinator.com/item?id=39865810

!codecels

Patch your shit if you're running Debian sid.

It seems that archlinux did ship it but the exploit doesn't work as they hadn't patched sshd against systemd and therefore liblzma. They have already pushed a fix regardless and I'm sure a lot of people will be combing through the code.

https://media.giphy.com/media/Pjr9CeaUbForwImKr1/giphy.webp


Follower of Christ :marseyandjesus: Tech lover, IT Admin, heckin pupper lover and occasionally troll. I hold back feelings or opinions, right or wrong because I dislike conflict.

Jump in the discussion.

No email address required.

https://i.rdrama.net/images/17117373969034464.webp

O REALLY???? R U SAYING PGP BAD??

Jump in the discussion.

No email address required.

This just in, supply chain attacks affect the supply chain

Jump in the discussion.

No email address required.

NOOOO MY SIG

Jump in the discussion.

No email address required.

>not using paid rdrama signatures to verify

:marseyitsover:

Jump in the discussion.

No email address required.

CapySec :#capyhacker: is the only security i trust to keep my cyberbussy safe and snug

Jump in the discussion.

No email address required.

lol that's a good bit.


Follower of Christ :marseyandjesus: Tech lover, IT Admin, heckin pupper lover and occasionally troll. I hold back feelings or opinions, right or wrong because I dislike conflict.

Jump in the discussion.

No email address required.

from ur sig I would trust your loads

Jump in the discussion.

No email address required.

I got tested three years ago and haven't had s*x since :marseythumbsup:

No pozzed loads here :marseyglow2:


Follower of Christ :marseyandjesus: Tech lover, IT Admin, heckin pupper lover and occasionally troll. I hold back feelings or opinions, right or wrong because I dislike conflict.

Jump in the discussion.

No email address required.

Yeah it goes that deep. Guy was clearly trusted by the maintainers :taygrimacing:


Follower of Christ :marseyandjesus: Tech lover, IT Admin, heckin pupper lover and occasionally troll. I hold back feelings or opinions, right or wrong because I dislike conflict.

Jump in the discussion.

No email address required.

Is steam deck okay?

Jump in the discussion.

No email address required.

I hope not

Jump in the discussion.

No email address required.

!codecels he chose violence https://media.giphy.com/media/1qfDU4MJv9xoGtRKvh/giphy.webp

Jump in the discussion.

No email address required.

No it's running an older version.

However this guy was involved with the project for two years so it wouldn't surprise me if people discover new vulnerabilities.


Follower of Christ :marseyandjesus: Tech lover, IT Admin, heckin pupper lover and occasionally troll. I hold back feelings or opinions, right or wrong because I dislike conflict.

Jump in the discussion.

No email address required.

That's a good question actually :marseyhmm:

Let me check


Follower of Christ :marseyandjesus: Tech lover, IT Admin, heckin pupper lover and occasionally troll. I hold back feelings or opinions, right or wrong because I dislike conflict.

Jump in the discussion.

No email address required.

hey dramabros can you help me understand?

like the chink got a "back door" what IS that actually? Like what can he do now? is he now just gonna ddos himself when his door starts calling?

Jump in the discussion.

No email address required.

If the circumstances are right (Debian-based system with patched sshd that links against systemd and liblzma) then the attacker can login to your system with no password.


Follower of Christ :marseyandjesus: Tech lover, IT Admin, heckin pupper lover and occasionally troll. I hold back feelings or opinions, right or wrong because I dislike conflict.

Jump in the discussion.

No email address required.

yea but he has like 1 million computers right? So how would he know who I am? and does it like send my infor to his server

Jump in the discussion.

No email address required.

I don't believe it phoned home but im not positive. I think this was a much longer play.

Considering he was at the project for two years and is Chinese, this could have been an attempt to build up an exploit for Chinese nationals to try in the future.

If it would have made it to Debian stable it would have been catastrophic.


Follower of Christ :marseyandjesus: Tech lover, IT Admin, heckin pupper lover and occasionally troll. I hold back feelings or opinions, right or wrong because I dislike conflict.

Jump in the discussion.

No email address required.

If it would have made it to Debian stable it would have been catastrophic.

this is very interesting. But how so? Like what does this do? How would he control it

Jump in the discussion.

No email address required.

He'd (China) be able to log into any exposed Debian server running this version with no password.

And there's A LOT of Debian servers.


Follower of Christ :marseyandjesus: Tech lover, IT Admin, heckin pupper lover and occasionally troll. I hold back feelings or opinions, right or wrong because I dislike conflict.

Jump in the discussion.

No email address required.

I'm surprised this doesn't happen more often tbh. You could make a lot of money out of posing as a legitimate developer for a while and then sneaking an exploit into a popular distribution.

Jump in the discussion.

No email address required.

https://i.rdrama.net/images/17117381718257816.webp

Jump in the discussion.

No email address required.

I guess people with talent would rather not be a target of the FBI?


Follower of Christ :marseyandjesus: Tech lover, IT Admin, heckin pupper lover and occasionally troll. I hold back feelings or opinions, right or wrong because I dislike conflict.

Jump in the discussion.

No email address required.

idk it's just in some people's personalities, there are lots of talented programmers doing shitty criminal stuff out there

Jump in the discussion.

No email address required.

It is certainly quite funny that c nerds constantly pearl clutch about supply chain attacks for javascript/rust and python and then one of the few "successful" cases happens to be in c.

Jump in the discussion.

No email address required.

because all important software is written in c. no real surprise

Jump in the discussion.

No email address required.

C should be renamed to L :marseyhmmhips:


Follower of Christ :marseyandjesus: Tech lover, IT Admin, heckin pupper lover and occasionally troll. I hold back feelings or opinions, right or wrong because I dislike conflict.

Jump in the discussion.

No email address required.

:marseywave#2:

Jump in the discussion.

No email address required.

None of this shit changes until these people start going to prison for things like this

Jump in the discussion.

No email address required.

I think he's on a return flight to Beijing at this point. This had to be a state op.


Follower of Christ :marseyandjesus: Tech lover, IT Admin, heckin pupper lover and occasionally troll. I hold back feelings or opinions, right or wrong because I dislike conflict.

Jump in the discussion.

No email address required.

Ok fine, I'll go to China and assassinate him myself then

Jump in the discussion.

No email address required.

:marseypatriot#talking:


Follower of Christ :marseyandjesus: Tech lover, IT Admin, heckin pupper lover and occasionally troll. I hold back feelings or opinions, right or wrong because I dislike conflict.

Jump in the discussion.

No email address required.

None of this shit changes

Jump in the discussion.

No email address required.

:#marseycringe:

Jump in the discussion.

No email address required.

Yeah pretty bad lol, very high chance this would have made it in many distros.


Follower of Christ :marseyandjesus: Tech lover, IT Admin, heckin pupper lover and occasionally troll. I hold back feelings or opinions, right or wrong because I dislike conflict.

Jump in the discussion.

No email address required.

Shit bros is this what the checksum is when I download stuff online ???

Jump in the discussion.

No email address required.

Kinda doubt a checksum would have helped here.

Jump in the discussion.

No email address required.

Checksums are kinda r-slurred, their only use is if you want to download some big archive from an untrusted mirror, and verify it with a checksum from a trusted source. But if you download the checksum and archive from the same host, they are completely pointless :marseydisagree:

Jump in the discussion.

No email address required.

I thought they offered them along with downloads so you could make sure the download wasn't corrupted, which also seemed r-slurred because I can just double click and find out

Jump in the discussion.

No email address required.

liblizma balls lmao

Jump in the discussion.

No email address required.

YTA for installing open sores software

any butthole can make changes to that shit

Jump in the discussion.

No email address required.

Now that you mention it I don't think I've ran into any anti-open source people in years. You used to hear stuff like that but now it's not even questioned.


Follower of Christ :marseyandjesus: Tech lover, IT Admin, heckin pupper lover and occasionally troll. I hold back feelings or opinions, right or wrong because I dislike conflict.

Jump in the discussion.

No email address required.

Jump in the discussion.

No email address required.

Link copied to clipboard
Action successful!
Error, please refresh the page and try again.