Unveiling the xz Utils Backdoor which deliberately opens our SSH connections for RCAs

https://www.youtube.com/watch?v=gyOz9s4ydho

99 points · 14 comments · view on lemmy.world

14 Comments

tsonfeir@lemm.ee · 32 pts · 2y (1 reply)

Anyone got a link for this topic that isn’t a video?

BOFH666@lemmy.world · 25 pts · 2y

https://tukaani.org/xz-backdoor/

Check the links on that page.

perishthethought@lemm.ee · 21 pts · 2y

Good explainer, if you need to catch up like I did:

https://en.m.wikipedia.org/wiki/XZ_Utils

Read the supply chain attack section.

Also, from the video...

X is losing its action! We LIKE!

Hell yeah we like.

BOFH666@lemmy.world · 14 pts · 2y (2 replies)

Thanks for the pointer.

This is really huge, but people don't quite understand that yet.

If this wasn't caught, every system -running public sshd- could be hacked or abused/misused.

And I completely agree with the last words, corporate should pay foss projects!

SMillerNL@lemmy.world · 7 pts · 2y (1 reply)

Even paid it might be hard to find maintainers with knowledge of the code

mudle@lemmy.ml · 10 pts · 2y

For all those wanting to know what version of the xz package you have, DO NOT use xz -V or xz --version. Ask your package manager instead; e.g. apt info xz-utils. Executing a potentially malicious binary IS NOT a good idea, so ask your package manager instead.

youngGoku@lemmy.world · 5 pts · 2y (6 replies)

So if I have been using arch with infected xz library to connect to a Debian LTS server, am I compromised?

cybersandwich@lemmy.world · 9 pts · 2y
[ removed ]
TwiddleTwaddle@lemmy.blahaj.zone · 6 pts · 2y (3 replies)

From what I've read both arch and debian stable aren't vulnerable to this. It targeted mostly debian-testing.

Irate1013@lemmy.ml · 3 pts · 2y

Arch put out a statement saying users should update to a non infected binary even though it doesn’t appear to affect Arch https://archlinux.org/news/the-xz-package-has-been-backdoored/

However, out of an abundance of caution, we advise users to remove the malicious code from their system by upgrading either way. This is because other yet-to-be discovered methods to exploit the backdoor could exist.

mosiacmango@lemm.ee · 1 pts · 2y
[ removed ]
rotopenguin@infosec.pub · 1 pts · 2y
[ removed ]
possiblylinux127@lemmy.zip · 1 pts · 2y

I would pay attention to the news. You definitely want to upgrade immediately if you have not already

j4yt33@feddit.de · 3 pts · 2y

I need the IASIP meme for this thumbnail

PipedLinkBot@feddit.rocks · 2 pts · 2y

Here is an alternative Piped link(s):

https://piped.video/watch?v=gyOz9s4ydho

Piped is a privacy-respecting open-source alternative frontend to YouTube.

I'm open-source; check me out at GitHub.

possiblylinux127@lemmy.zip · 2 pts · 2y

That thumbnail is something else