128,267 views
???? How to take over the world? Well. Maybe all it takes is years of patience, great skills, and very deep pockets. But above all, you have to not be unlucky, because it was luck that saved us all from disaster. What's the deal? Sources: ???? Tukaani project website, of which xz is a part https://tukaani.org/xz-backdoor/ ???? backdoor in upstream xz/liblzma leading to ssh server compromise [email protected] https://www.openwall.com/lists/oss-se... ???? Debian Bug report logs - #778913 openssh-server: init (at least systemd) t notice when sshd fails to start and reports success https://bugs.debian.org/cgi-bin/bugre... ???? Techies vs spies: the xz backdoor debate https://lcamtuf.substack.com/p/techno... ???? OSS backdoors: the folly of the easy fix https://lcamtuf.substack.com/p/oss-ba... ???? xz-utils: New upstream version available https://bugs.debian.org/cgi-bin/bugre... ???? xz/liblzma: Bash-stage Obfuscation Explained https://gynvael.coldwind.pl/?lang=en&... ???? The Mystery of 'Jia Tan,' the XZ Backdoor Mastermind https://www.wired.com/story/jia-tan-x... ???? Everything I Know About the XZ Back door https://boehs.org/node/everything-ik... ⏳ https://github.com/lockness-Ko/xz-vul... ???? Bullying in Open Source Software Is a Massive Security Vulnerability https://www.404media.co/xz-backdoor-b... ⏲️ Alex Volkov (Thursd/AI) @Twixxer / 1774504915357892688 ???? CVE-2024-3094 in the NIST database https://nvd.nist.gov/vuln/detail/CVE-... ???? Infographic presenting the attack scheme, Thomas Roccia @Twixxer / 1774342248437813525 ???? The attack on xz is not an access control bypass. It's RCE. https://bsky.app/profile/filippo.abys... ‼️ The scandal around XZ. Attempt to mine the digital world https://www.ciemnastrona.com.pl/cyfro... ???? How did they try to attack f-droid? https://social.librem.one/@eighthave/... Relevant xkcd: https://xkcd.com/2347/ © All trademarks are property of their rightful owners. ❤️ Thank you for your attention. You can also find me on: Instagram @mateuszemsi / mateuszemsi Twitter @MateuszChrobok / mateuszchrobok Mastodon https://infosec.exchange/@mateuszchrobok LinkedIn @mateuszchrobok / mateuszchrobok Patronite @MateuszChrobok https://patronite.pl/MateuszChrobok Podcasts on: Anchor https://anchor.fm/mateusz-chrobok Spotify https://open.spotify.com/show/6y6oWs2... Apple Podcasts https://apple.co/3OwjvOh Chapters: 00:00 Intro 02:01 Timeline 07:11 Easter 11:33 Mechanism 17:16 Attribution 22:01 What to Do and How to Live? #xz #ssh #attack #APT #linux