Lädt...

📰 The amazingly scary xz sshd backdoor, (Mon, Apr 1st)


Nachrichtenbereich: 📰 IT Security
🔗 Quelle: isc.sans.edu

Unless you took the whole weekend off, you must have seen by now that Andres Freund published an amazing discovery on Friday on the Openwall mailing list (https://www.openwall.com/lists/oss-security/2024/03/29/4).
The whole story around this is both fascinating and scary – and I'm sure will be told around numerous time, so in this diary I will put some technical things about the backdoor that I reversed for quite some time (and I have a feeling I could spend 2 more weeks on this).
There is also a nice gist by smx-smx here that gets updated regularly so keep an eye there as well.
The author(s) of the backdoor went a long way to make the backdoor look as innocent as possible. This is also why all the reversing effort is taking such a long(er) time. Let's take a look at couple of fascinating things in this backdoor.

...

📰 The amazingly scary xz sshd backdoor, (Mon, Apr 1st)


📈 107.96 Punkte
📰 IT Security

📰 ISC Stormcast For Monday, April 1st, 2024 https://isc.sans.edu/podcastdetail/8918, (Mon, Apr 1st)


📈 53.44 Punkte
📰 IT Security

📰 The xz-utils backdoor in security advisories by national CSIRTs, (Mon, Apr 1st)


📈 46.74 Punkte
📰 IT Security

📰 SSHD-Poison - A Tool To Get Creds Of Pam Based SSHD Authentication


📈 40.84 Punkte
📰 IT Security Nachrichten

📰 SSHD-Poison - A Tool To Get Creds Of Pam Based SSHD Authentication


📈 40.84 Punkte
📰 IT Security Nachrichten

📰 ISC Stormcast For Monday, March 1st, 2021 https://isc.sans.edu/podcastdetail.html?id=7392, (Mon, Mar 1st)


📈 39.65 Punkte
📰 IT Security

📰 ISC Stormcast For Monday, June 1st 2020 https://isc.sans.edu/podcastdetail.html?id=7018, (Mon, Jun 1st)


📈 39.65 Punkte
📰 IT Security

📰 D-Link NAS Device Backdoor Abused, (Mon, Apr 29th)


📈 32.34 Punkte
📰 IT Security

🕵️ Kèo Thẻ Phạt Vip66 Là Gì? 3 Lối Đánh Kèo Chậm Mà Chắc


📈 30.16 Punkte
🕵️ Reverse Engineering

🔧 KISS Principle: Giữ Mọi Thứ Đơn Giản Nhất Có Thể


📈 30.16 Punkte
🔧 Programmierung

🔧 Có thể bạn chưa biết (Phần 1)


📈 30.16 Punkte
🔧 Programmierung

🔧 Tìm Hiểu Về RAG: Công Nghệ Đột Phá Đang "Làm Mưa Làm Gió" Trong Thế Giới Chatbot


📈 30.16 Punkte
🔧 Programmierung

🔧 Multimodal RAG Is Not Scary, Ghosts Are Scary


📈 30.06 Punkte
🔧 Programmierung

📰 ISC Stormcast For Wednesday, May 1st, 2024 https://isc.sans.edu/podcastdetail/8962, (Wed, May 1st)


📈 28.8 Punkte
📰 IT Security

📰 ISC Stormcast For Friday, March 1st, 2024 https://isc.sans.edu/podcastdetail/8876, (Fri, Mar 1st)


📈 28.8 Punkte
📰 IT Security

📰 ISC Stormcast For Thursday, February 1st, 2024 https://isc.sans.edu/podcastdetail/8834, (Thu, Feb 1st)


📈 28.8 Punkte
📰 IT Security

📰 ISC Stormcast For Friday, December 1st, 2023 https://isc.sans.edu/podcastdetail/8760, (Fri, Dec 1st)


📈 28.8 Punkte
📰 IT Security

📰 ISC Stormcast For Wednesday, November 1st, 2023 https://isc.sans.edu/podcastdetail/8726, (Wed, Nov 1st)


📈 28.8 Punkte
📰 IT Security

matomo