How did half a second save the world from destruction?

128,267 views

Mateusz Chrobok

Published on Apr 7, 2024
About :

???? How to take over the world? Well. Maybe all it takes is years of patience, great skills, and very deep pockets. But above all, you have to not be unlucky, because it was luck that saved us all from disaster. What's the deal? Sources: ???? Tukaani project website, of which xz is a part https://tukaani.org/xz-backdoor/ ???? backdoor in upstream xz/liblzma leading to ssh server compromise [email protected] https://www.openwall.com/lists/oss-se... ???? Debian Bug report logs - #778913 openssh-server: init (at least systemd) t notice when sshd fails to start and reports success https://bugs.debian.org/cgi-bin/bugre... ???? Techies vs spies: the xz backdoor debate https://lcamtuf.substack.com/p/techno... ???? OSS backdoors: the folly of the easy fix https://lcamtuf.substack.com/p/oss-ba... ???? xz-utils: New upstream version available https://bugs.debian.org/cgi-bin/bugre... ???? xz/liblzma: Bash-stage Obfuscation Explained https://gynvael.coldwind.pl/?lang=en&... ???? The Mystery of 'Jia Tan,' the XZ Backdoor Mastermind https://www.wired.com/story/jia-tan-x... ???? Everything I Know About the XZ Back door https://boehs.org/node/everything-ik... ⏳ https://github.com/lockness-Ko/xz-vul... ???? Bullying in Open Source Software Is a Massive Security Vulnerability https://www.404media.co/xz-backdoor-b... ⏲️ Alex Volkov (Thursd/AI) @Twixxer / 1774504915357892688 ???? CVE-2024-3094 in the NIST database https://nvd.nist.gov/vuln/detail/CVE-... ???? Infographic presenting the attack scheme, Thomas Roccia @Twixxer / 1774342248437813525 ???? The attack on xz is not an access control bypass. It's RCE. https://bsky.app/profile/filippo.abys... ‼️ The scandal around XZ. Attempt to mine the digital world https://www.ciemnastrona.com.pl/cyfro... ???? How did they try to attack f-droid? https://social.librem.one/@eighthave/... Relevant xkcd: https://xkcd.com/2347/ © All trademarks are property of their rightful owners. ❤️ Thank you for your attention. You can also find me on: Instagram @mateuszemsi / mateuszemsi Twitter @MateuszChrobok / mateuszchrobok Mastodon https://infosec.exchange/@mateuszchrobok LinkedIn @mateuszchrobok / mateuszchrobok Patronite @MateuszChrobok https://patronite.pl/MateuszChrobok Podcasts on: Anchor https://anchor.fm/mateusz-chrobok Spotify https://open.spotify.com/show/6y6oWs2... Apple Podcasts https://apple.co/3OwjvOh Chapters: 00:00 Intro 02:01 Timeline 07:11 Easter 11:33 Mechanism 17:16 Attribution 22:01 What to Do and How to Live? #xz #ssh #attack #APT #linux

Trend Videos
36:18
20:20
10:25
4,224,862 views   12 days ago
3:20
39:16
24:37
573,609 views   1 day ago
7:20
1,693,821 views   13 days ago
39:16
Google AdSense
336 x 280
Up Next
9:34
らだぺでぃあ【らっだぁ公認切り抜きCh】
78,472 views
6 months ago
9:33
らだぺでぃあ【らっだぁ公認切り抜きCh】
72,243 views
5 months ago
17:01
らだぺでぃあ【らっだぁ公認切り抜きCh】
267,026 views
6 months ago
22:07
5:29
【切り抜き集】らっだぁの他力本願寺
194,840 views
6 months ago
45:17
らだぺでぃあ【らっだぁ公認切り抜きCh】
191,994 views
5 months ago
5:12
【切り抜き集】らっだぁの他力本願寺
293,967 views
5 months ago
2:38:00
【切り抜き集】らっだぁの他力本願寺
568,601 views
4 months ago
10:35
Lucas Mariani Violão
314,250 views
3 years ago
10:13
Lucas Mariani Violão
118,097 views
4 years ago
4:23
Eduardo Costa
88,204,358 views
6 years ago
5:11
9:44
Lucas Mariani Violão
198,694 views
3 years ago
4:42
Eduardo Costa
11,136,747 views
3 years ago
9:19
Lucas Mariani Violão
351,808 views
3 years ago
9:01
Lucas Mariani Violão
1,078,177 views
3 years ago
6:31
Renan Zimmer
3,519 views
5 months ago
3:31
Pega a Guitarra - Pega o Violão - Bonfim Estúdio
46,008 views
6 months ago
13:03
Lucas Mariani Violão
163,518 views
3 years ago
8:53
Lucas Mariani Violão
226,215 views
3 years ago
18:42
Renan Zimmer
270,022 views
1 year ago
6:53
Renan Zimmer
7,508 views
4 months ago
3:59
17:36
Jaime Toledo
3,529 views
2 years ago
9:44
Lucas Mariani Violão
121,514 views
3 years ago
Google AdSense
336 x 280

fetery.com. Copyright 2024