Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.user > #268637

Re: making Debian secure by default

From Marc SCHAEFER <schaefer@alphanet.ch>
Newsgroups linux.debian.user
Subject Re: making Debian secure by default
Date 2024-03-30 12:40 +0100
Message-ID <InFe1-2KkK-3@gated-at.bofh.it> (permalink)
References (3 earlier) <Inp9f-2A8j-9@gated-at.bofh.it> <Inp9f-2A8j-11@gated-at.bofh.it> <Inp9f-2A8j-13@gated-at.bofh.it> <Inp9f-2A8j-15@gated-at.bofh.it> <Inp9f-2A8j-1@gated-at.bofh.it>
Organization linux.* mail to news gateway

Show all headers | View raw


Hello,

On Fri, Mar 29, 2024 at 07:02:54PM +0100, Kamil Jo?ca wrote:
> O-o, is there any simple test to check if I have infected version or
> not?

For example, under root:

  path="$(ldd $(which sshd) | grep liblzma | grep -o '/[^ ]*')"
   if hexdump -ve '1/1 "%.2x"' "$path" | grep -q  f30f1efa554889f54c89ce5389fb81e7000000804883ec28488954241848894c2410
   then
        echo probably vulnerable
   else
        echo probably not vulnerable
   fi

NB: always think and read before typing root commands, or any commands
you find on a forum or mailing-list :)

More info:
   https://boehs.org/node/everything-i-know-about-the-xz-backdoor
      Interesting read about social interactions

   https://www.openwall.com/lists/oss-security/2024/03/29/4
      ref for the code above

   https://www.openwall.com/lists/oss-security/2024/03/29/23
      idea to confine the sshd -> systemd dependancy,
      in a specific process, because of the huge systemd
      attack surface

Back to linux.debian.user | Previous | Next — Previous in thread | Find similar | Unroll thread


Thread

Re: making Debian secure by default Kamil Jońca <kjonca@o2.pl> - 2024-03-29 19:30 +0100
  Re: making Debian secure by default Andy Smith <andy@strugglers.net> - 2024-03-29 21:10 +0100
  Re: making Debian secure by default Marc SCHAEFER <schaefer@alphanet.ch> - 2024-03-30 12:40 +0100

csiph-web