#XZBackdoor
Scanning the #xzbackdoor has been made tough.
Keep your netflows well archived!
Apparently the backdoor reverts back to regular operation if the payload is malformed or the signature from the attacker's key doesn't verify.

Unfortunately, this means that unless a bug is found, we can't write a reliable/reusable over-the-network scanner.
April 1, 2024 at 1:01 AM
April 15, 2024 at 10:16 AM
Et on s'interroge sur tout l'écosystème qui permet ce genre de trucs... #xzbackdoor
April 3, 2024 at 6:40 AM
Wer ist Jia Tan? Eine interessant zu lesende Spurensuche von Marcel Waldvogel anhand von technischen Indizien zu Zeitzonen, Verhalten, Motive, Aufwand.

#dnip
#xzbackdoor #opensource #ssh
Wer ist «Jia Tan»? Eine Spurensuche zur xz-Backdoor - Das Netz ist politisch
Über ein Monat ist vergangen und wir wissen immer noch nicht viel über die Hintergründe und Hintermänner der xz-Backdoor. Dies, obwohl die Lücke im besten
dnip.ch
May 15, 2024 at 9:42 AM
The xz attack shell script by Russ Cox

A detailed look at the autoconf side of #xzbackdoor

https://research.swtch.com/xz-script

h/t @wtfpdf


Original post
April 2, 2024 at 8:09 PM
TODO: ergänze das Bild mit: „oder er könnte der Typ sein, der Schadcode unter wirrem Zeug verstecken will“. #xz #xzbackdoor #infosec
March 31, 2024 at 1:17 PM
« Encore une fois l'#opensource a prouvé sa vigilance et proactivité dans la détection de #xzbackdoor, le niveau de transparence est stratosphérique par rapport au logiciel propriétaire ; ce qui a été accompli en 24h mérite un moment d'humilité [...] »
Par social.wildeboer.net/@jwildeboer
March 31, 2024 at 4:13 PM
¡Directo de desarrollo de juegos y #ciberseguridad!

Vamos a hablar de todo lo ocurrido este fin de semana con "XZ Backdoor".

Aunque no seáis personas muy técnicas... hay una parte muy interesante de ingeniería social 👀

👉 twitch.tv/rafalagoon

#gamedev #xzbackdoor #floss #ciberseguridad #linux
April 2, 2024 at 10:30 AM
HOLY FAFF PEOPLE !!

THE #XZ BACKDOOR IS RCE NOT JUST AUTH BYPASS !!!!

NUKE XZ FROM YOUR SYSTEMS A.S.A.P IF AT ALL POSSIBLE !!!!!!

#ITSecurity #XZBackdoor
I'm watching some folks reverse engineer the xz backdoor, sharing some *preliminary* analysis with permission.

The hooked RSA_public_decrypt verifies a signature on the server's host key by a fixed Ed448 key, and then passes a payload to system().

It's RCE, not auth bypass, and gated/unreplayable.
This might be the best executed supply chain attack we've seen described in the open, and it's a nightmare scenario: malicious, competent, authorized upstream in a widely used library.

Looks like this got caught by chance. Wonder how long it would have taken otherwise.
March 31, 2024 at 1:25 PM
Ach, guck, diese #xzbackdoor wurde durch einen Mitarbeiter von #Microsoft aufgedeckt? Aber immer schön auf den Laden schimpfen. Und ja, ich bin spät dran.
April 6, 2024 at 5:30 PM
Et le pire, c'est que la catastrophe a été évitée par le plus grand des hasards. Inévitablement, on se demande s'il y a d'autres tentatives du même genre... #xzbackdoor
April 3, 2024 at 6:37 AM
My ex-colleague said that his organisation is not affected by #xzbackdoor, because they hadn't updated any package for years. You can't download a malware if you don't download anything
April 1, 2024 at 6:39 PM
> boehs.org/node/everyth... has a more detailed timeline of events.

Via: x.com/GrapheneOS/s...

#xzbackdoor
Everything I know about the XZ backdoor
Please note: This is being updated in real time. The intent is to make sense of lots of simultaneous discoveries
boehs.org
March 29, 2024 at 11:27 PM
The discovery of #xzbackdoor is a reminder of no matter how small the problem you work on seems, you can find something significant as long as you are willing to dig deep enough to understand how things work.


Original post
April 1, 2024 at 9:02 AM
Not April Fools’: first Weekly Reckoning of April out now! Feat. my take on Voice Engine, the #xzbackdoor, Florida banning kids from social media, and, crucially, advancements in AI beer. Tied all together with musings on how peer review and OS software development are broken.
#newsletter #STS
WR 22: The volunteers keeping science & software afloat; AI beer
Weekly Reckoning for the week of 1/4/24
ethicalreckoner.substack.com
April 1, 2024 at 1:37 PM
Was meint ihr: Die Tatsache, dass die #xzbackdoor aufgeflogen ist, hat das den Markt von Sicherheitslücken gestört oder bleibt dieser weiter unbeeindruckt?
April 9, 2024 at 8:50 PM
XZ Utils Backdoor Persists in 35+ Docker Hub Images Over Year After Discovery XZ Utils backdoor found in 35+ Docker Hub images over year after discovery. #XZBackdoor #Docker #SupplyChain The post X...

#TIGR #malware

Origin | Interest | Match
Awakari App
awakari.com
August 13, 2025 at 9:41 PM
The public launch of OTF's #foss #sustainability #fund could not have been more timely 💜

#xzbackdoor #xz #security #developers #burnout

www.opentech.fund/funds/free-a...
Free and Open Source Software Sustainability Fund
www.opentech.fund
April 3, 2024 at 8:41 PM
bl4sty uncovers some more functionality of the #xzbackdoor :

https://nitter.poast.org/bl4sty/status/1776691497506623562#m


Original post
April 7, 2024 at 6:41 PM
The #xzbackdoor was clearly well planned and attackers most likely had plans for when their code is widely deployed.

Assuming this root RCE over SSH on a vast number of hosts, how would your RCE payload look like?


Original post
April 1, 2024 at 12:31 PM
🐛 What we know about the xz Utils backdoor that almost infected the world
by Dan Goodin @dangoodin001 dan.goodin@arstechnica.com at @arstechnica
#XZbackdoor #xzUtils #malware

arstechnica.com/security/202...
April 1, 2024 at 11:02 PM
🟢Everything I Know About the XZ Backdoor
by Evan Boehs @eb@social.coop
#XZbackdoor #webdev #Security

boehs.org/node/everyth...
April 1, 2024 at 10:53 PM
On Friday, a lone Microsoft developer rocked the world when he revealed a backdoor had been intentionally planted in xz Utils #xzbackdoor arstechnica.com/security/202...
April 1, 2024 at 7:41 PM