Keep your netflows well archived!
Unfortunately, this means that unless a bug is found, we can't write a reliable/reusable over-the-network scanner.
Keep your netflows well archived!
#dnip
#xzbackdoor #opensource #ssh
#dnip
#xzbackdoor #opensource #ssh
A detailed look at the autoconf side of #xzbackdoor
https://research.swtch.com/xz-script
h/t @wtfpdf
Original post
A detailed look at the autoconf side of #xzbackdoor
https://research.swtch.com/xz-script
h/t @wtfpdf
Original post
Par social.wildeboer.net/@jwildeboer
Par social.wildeboer.net/@jwildeboer
Vamos a hablar de todo lo ocurrido este fin de semana con "XZ Backdoor".
Aunque no seáis personas muy técnicas... hay una parte muy interesante de ingeniería social 👀
👉 twitch.tv/rafalagoon
#gamedev #xzbackdoor #floss #ciberseguridad #linux
Vamos a hablar de todo lo ocurrido este fin de semana con "XZ Backdoor".
Aunque no seáis personas muy técnicas... hay una parte muy interesante de ingeniería social 👀
👉 twitch.tv/rafalagoon
#gamedev #xzbackdoor #floss #ciberseguridad #linux
THE #XZ BACKDOOR IS RCE NOT JUST AUTH BYPASS !!!!
NUKE XZ FROM YOUR SYSTEMS A.S.A.P IF AT ALL POSSIBLE !!!!!!
#ITSecurity #XZBackdoor
The hooked RSA_public_decrypt verifies a signature on the server's host key by a fixed Ed448 key, and then passes a payload to system().
It's RCE, not auth bypass, and gated/unreplayable.
Looks like this got caught by chance. Wonder how long it would have taken otherwise.
THE #XZ BACKDOOR IS RCE NOT JUST AUTH BYPASS !!!!
NUKE XZ FROM YOUR SYSTEMS A.S.A.P IF AT ALL POSSIBLE !!!!!!
#ITSecurity #XZBackdoor
Via: x.com/GrapheneOS/s...
#xzbackdoor
Via: x.com/GrapheneOS/s...
#xzbackdoor
Original post
Original post
#newsletter #STS
#newsletter #STS
#Cyberangriffe #ITSicherheit #Malware #Softwareentwicklung #chalk #Cybersicherheit #debug #javascript #Kryptowährung #NPM #Phishing #Sicherheit #SupplyChainAngriff #XZBackdoor
#xzbackdoor #xz #security #developers #burnout
www.opentech.fund/funds/free-a...
#xzbackdoor #xz #security #developers #burnout
www.opentech.fund/funds/free-a...
https://nitter.poast.org/bl4sty/status/1776691497506623562#m
Original post
https://nitter.poast.org/bl4sty/status/1776691497506623562#m
Original post
Assuming this root RCE over SSH on a vast number of hosts, how would your RCE payload look like?
Original post
Assuming this root RCE over SSH on a vast number of hosts, how would your RCE payload look like?
Original post
by Dan Goodin @dangoodin001 dan.goodin@arstechnica.com at @arstechnica
#XZbackdoor #xzUtils #malware
arstechnica.com/security/202...
by Dan Goodin @dangoodin001 dan.goodin@arstechnica.com at @arstechnica
#XZbackdoor #xzUtils #malware
arstechnica.com/security/202...
by Evan Boehs @eb@social.coop
#XZbackdoor #webdev #Security
boehs.org/node/everyth...
by Evan Boehs @eb@social.coop
#XZbackdoor #webdev #Security
boehs.org/node/everyth...