Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.debian.user > #268637
| From | Marc SCHAEFER <schaefer@alphanet.ch> |
|---|---|
| Newsgroups | linux.debian.user |
| Subject | Re: making Debian secure by default |
| Date | 2024-03-30 12:40 +0100 |
| Message-ID | <InFe1-2KkK-3@gated-at.bofh.it> (permalink) |
| References | (3 earlier) <Inp9f-2A8j-9@gated-at.bofh.it> <Inp9f-2A8j-11@gated-at.bofh.it> <Inp9f-2A8j-13@gated-at.bofh.it> <Inp9f-2A8j-15@gated-at.bofh.it> <Inp9f-2A8j-1@gated-at.bofh.it> |
| Organization | linux.* mail to news gateway |
Hello,
On Fri, Mar 29, 2024 at 07:02:54PM +0100, Kamil Jo?ca wrote:
> O-o, is there any simple test to check if I have infected version or
> not?
For example, under root:
path="$(ldd $(which sshd) | grep liblzma | grep -o '/[^ ]*')"
if hexdump -ve '1/1 "%.2x"' "$path" | grep -q f30f1efa554889f54c89ce5389fb81e7000000804883ec28488954241848894c2410
then
echo probably vulnerable
else
echo probably not vulnerable
fi
NB: always think and read before typing root commands, or any commands
you find on a forum or mailing-list :)
More info:
https://boehs.org/node/everything-i-know-about-the-xz-backdoor
Interesting read about social interactions
https://www.openwall.com/lists/oss-security/2024/03/29/4
ref for the code above
https://www.openwall.com/lists/oss-security/2024/03/29/23
idea to confine the sshd -> systemd dependancy,
in a specific process, because of the huge systemd
attack surface
Back to linux.debian.user | Previous | Next — Previous in thread | Find similar | Unroll thread
Re: making Debian secure by default Kamil Jońca <kjonca@o2.pl> - 2024-03-29 19:30 +0100 Re: making Debian secure by default Andy Smith <andy@strugglers.net> - 2024-03-29 21:10 +0100 Re: making Debian secure by default Marc SCHAEFER <schaefer@alphanet.ch> - 2024-03-30 12:40 +0100
csiph-web