![]() |
|
|
|
#1
|
|||
|
|||
|
What is absolutely ingenious is that they put the payload into a test blob as it looks like merely garbage being used for automated testing to verify liblzma. Basically an innocuous place noone would think to look or cate about. Some of the bash scripts are fascinating in this. What's interesting is that the Microsoft engineer noticed a 0.5 second delay in SSH because a mistake was made, and fir whatever reason the engineer managed to investigate and pinpoint that it is a backdoor. The whole thing is pretty amazing. Makes you wonder how many other open source projects are backdoored but noone noticed or investigated. Kind of scary.
|
| The Following 2 Users Say Thank You to chants For This Useful Post: | ||
blue_devil (04-02-2024), uranus64 (04-02-2024) | ||
|
#2
|
||||
|
||||
|
Quote:
If you are interested in state-sponsored-hackers. You should also read how Ken Thompson injected a virus to a compiler. Code:
https://wiki.c2.com/?TheKenThompsonHack |
![]() |
| Tags |
| liblzma, state sponsored hackers, trojan, xz lossless compression |
| Thread Tools | |
| Display Modes | |
|
|
Similar Threads
|
||||
| Thread | Thread Starter | Forum | Replies | Last Post |
| How come new registrants given "guest" rank and not even a "friend" rank? | OldieHans | General Discussion | 4 | 09-25-2023 12:19 |
| When use "vendor defined encryption routines", how to set daemon related part? | bridgeic | General Discussion | 6 | 01-22-2015 11:35 |
| Wlscgen: Are "Vendor Id" and "Developer Id" different ? | Numega Softice | General Discussion | 6 | 02-12-2007 18:12 |