MacMusic  |  PcMusic  |  440 Software  |  440 Forums  |  440TV  |  Zicos
backdoor
Recherche

[$] How the XZ backdoor works

mardi 2 avril 2024, 22:41 , par LWN.net
Versions 5.6.0 and 5.6.1 of the
XZ
compression utility and library
were shipped with a backdoor that targeted
OpenSSH.
Andres Freund

discovered the backdoor by
noticing that failed SSH logins were taking a lot of
CPU time while doing some
micro-benchmarking, and tracking down the backdoor from there. It was introduced
by XZ co-maintainer 'Jia Tan' — a probable alias for person or persons unknown.
The backdoor is a sophisticated attack with multiple parts, from the build
system, to link time, to run time.
https://lwn.net/Articles/967192/

Voir aussi

News copyright owned by their original publishers | Copyright © 2004 - 2024 Zicos / 440Network
Date Actuelle
jeu. 2 mai - 21:45 CEST