How did half a second save the world from destruction?

128,267 views

Mateusz Chrobok

Published on Apr 7, 2024
About :

???? How to take over the world? Well. Maybe all it takes is years of patience, great skills, and very deep pockets. But above all, you have to not be unlucky, because it was luck that saved us all from disaster. What's the deal? Sources: ???? Tukaani project website, of which xz is a part https://tukaani.org/xz-backdoor/ ???? backdoor in upstream xz/liblzma leading to ssh server compromise [email protected] https://www.openwall.com/lists/oss-se... ???? Debian Bug report logs - #778913 openssh-server: init (at least systemd) t notice when sshd fails to start and reports success https://bugs.debian.org/cgi-bin/bugre... ???? Techies vs spies: the xz backdoor debate https://lcamtuf.substack.com/p/techno... ???? OSS backdoors: the folly of the easy fix https://lcamtuf.substack.com/p/oss-ba... ???? xz-utils: New upstream version available https://bugs.debian.org/cgi-bin/bugre... ???? xz/liblzma: Bash-stage Obfuscation Explained https://gynvael.coldwind.pl/?lang=en&... ???? The Mystery of 'Jia Tan,' the XZ Backdoor Mastermind https://www.wired.com/story/jia-tan-x... ???? Everything I Know About the XZ Back door https://boehs.org/node/everything-ik... ⏳ https://github.com/lockness-Ko/xz-vul... ???? Bullying in Open Source Software Is a Massive Security Vulnerability https://www.404media.co/xz-backdoor-b... ⏲️ Alex Volkov (Thursd/AI) @Twixxer / 1774504915357892688 ???? CVE-2024-3094 in the NIST database https://nvd.nist.gov/vuln/detail/CVE-... ???? Infographic presenting the attack scheme, Thomas Roccia @Twixxer / 1774342248437813525 ???? The attack on xz is not an access control bypass. It's RCE. https://bsky.app/profile/filippo.abys... ‼️ The scandal around XZ. Attempt to mine the digital world https://www.ciemnastrona.com.pl/cyfro... ???? How did they try to attack f-droid? https://social.librem.one/@eighthave/... Relevant xkcd: https://xkcd.com/2347/ © All trademarks are property of their rightful owners. ❤️ Thank you for your attention. You can also find me on: Instagram @mateuszemsi / mateuszemsi Twitter @MateuszChrobok / mateuszchrobok Mastodon https://infosec.exchange/@mateuszchrobok LinkedIn @mateuszchrobok / mateuszchrobok Patronite @MateuszChrobok https://patronite.pl/MateuszChrobok Podcasts on: Anchor https://anchor.fm/mateusz-chrobok Spotify https://open.spotify.com/show/6y6oWs2... Apple Podcasts https://apple.co/3OwjvOh Chapters: 00:00 Intro 02:01 Timeline 07:11 Easter 11:33 Mechanism 17:16 Attribution 22:01 What to Do and How to Live? #xz #ssh #attack #APT #linux

Trend Videos
8:45
26:37
11:12
682,437 views   7 days ago
32:13
Google AdSense
336 x 280
Up Next
1:01:13
좁은 길, 생명의 길(생명의 말씀)
31,418 views
10 days ago
1:18:26
21일간 열방과 함께하는 다니엘기도회
60,252 views
9 hours ago
1:44:05
gasir styner
134,855 views
11 years ago
1:34:38
Cornerstone Korean Baptist Church Carrollton
238,455 views
Streamed 1 year ago
1:28:03
Cornerstone Korean Baptist Church Carrollton
164,135 views
Streamed 1 year ago
1:01:02
SpiritualTV / 시대영성TV / 정치 / 정보
32,269 views
7 months ago
38:37
좁은 길, 생명의 길(생명의 말씀)
20,608 views
11 days ago
54:02
좁은 길, 생명의 길(생명의 말씀)
29,435 views
2 months ago
1:24:59
Monmouth Grace UMC (만모스 은혜 연합교회)
439,003 views
8 years ago
1:24:06
크리스천설교채널 : C1 TV
63,189 views
4 years ago
1:28:27
Cornerstone Korean Baptist Church Carrollton
170,568 views
Streamed 1 year ago
31:22
Русская Дымка
6,345 views
2 years ago
44:06
Как сварить пиво Стратегия 21
8,320 views
3 years ago
28:39
25:32
Домашняя пивоварня Ezhoff beer
8,229 views
2 years ago
28:37
КОЛБА
10,001 views
3 years ago
31:58
DeMeurg
149,731 views
7 years ago
19:14
Домашняя пивоварня Ezhoff beer
13,366 views
3 years ago
29:05
Сельский кадр
91,141 views
3 years ago
40:49
Самозванцы
296,724 views
4 years ago
20:44
Домашний пивовар ВамБир
6,098 views
3 years ago
27:03
Not Bad Beer
30,938 views
3 years ago
17:57
Мужики у плиты
6,385 views
1 year ago
14:13
Липецкий Пивовар
23,748 views
3 years ago
Google AdSense
336 x 280

fetery.com. Copyright 2024