Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.user > #268627 > unrolled thread

Re: making Debian secure by default

Started byKamil Jońca <kjonca@o2.pl>
First post2024-03-29 19:30 +0100
Last post2024-03-30 12:40 +0100
Articles 3 — 3 participants

Back to article view | Back to linux.debian.user

This discussion starts older than the indexed window; earlier articles aren't shown. The article labeled Started by below is the oldest one visible, not the original post.


Contents

  Re: making Debian secure by default Kamil Jońca <kjonca@o2.pl> - 2024-03-29 19:30 +0100
    Re: making Debian secure by default Andy Smith <andy@strugglers.net> - 2024-03-29 21:10 +0100
    Re: making Debian secure by default Marc SCHAEFER <schaefer@alphanet.ch> - 2024-03-30 12:40 +0100

#268627 — Re: making Debian secure by default

FromKamil Jońca <kjonca@o2.pl>
Date2024-03-29 19:30 +0100
SubjectRe: making Debian secure by default
Message-ID<Inp9f-2A8j-1@gated-at.bofh.it>
Andy Smith <andy@strugglers.net> writes:

[...]
> https://www.openwall.com/lists/oss-security/2024/03/29/4
>
> (Upstream xz/lzma project compromised, hostile code inserted into
> sshd in Debian sid and other leading edge distros.)
>
> Thanks,
> Andy

O-o, is there any simple test to check if I have infected version or
not?
KJ
-- 
http://wolnelektury.pl/wesprzyj/teraz/

[toc] | [next] | [standalone]


#268633

FromAndy Smith <andy@strugglers.net>
Date2024-03-29 21:10 +0100
Message-ID<InqI1-2BdI-7@gated-at.bofh.it>
In reply to#268627
Hello,

On Fri, Mar 29, 2024 at 07:02:54PM +0100, Kamil Jońca wrote:
> Andy Smith <andy@strugglers.net> writes:
> > https://www.openwall.com/lists/oss-security/2024/03/29/4
> >
> > (Upstream xz/lzma project compromised, hostile code inserted into
> > sshd in Debian sid and other leading edge distros.)
> 
> O-o, is there any simple test to check if I have infected version or
> not?

Reading the link fully would show you how, but as far as Debian ics
concerned it only made it to testing and sid. If you run either of
those then Debian's own security announcements cover it.

Thanks,
Andy

-- 
https://bitfolk.com/ -- No-nonsense VPS hosting

[toc] | [prev] | [next] | [standalone]


#268637

FromMarc SCHAEFER <schaefer@alphanet.ch>
Date2024-03-30 12:40 +0100
Message-ID<InFe1-2KkK-3@gated-at.bofh.it>
In reply to#268627
Hello,

On Fri, Mar 29, 2024 at 07:02:54PM +0100, Kamil Jo?ca wrote:
> O-o, is there any simple test to check if I have infected version or
> not?

For example, under root:

  path="$(ldd $(which sshd) | grep liblzma | grep -o '/[^ ]*')"
   if hexdump -ve '1/1 "%.2x"' "$path" | grep -q  f30f1efa554889f54c89ce5389fb81e7000000804883ec28488954241848894c2410
   then
        echo probably vulnerable
   else
        echo probably not vulnerable
   fi

NB: always think and read before typing root commands, or any commands
you find on a forum or mailing-list :)

More info:
   https://boehs.org/node/everything-i-know-about-the-xz-backdoor
      Interesting read about social interactions

   https://www.openwall.com/lists/oss-security/2024/03/29/4
      ref for the code above

   https://www.openwall.com/lists/oss-security/2024/03/29/23
      idea to confine the sshd -> systemd dependancy,
      in a specific process, because of the huge systemd
      attack surface

[toc] | [prev] | [standalone]


Back to top | Article view | linux.debian.user


csiph-web