Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.debian.user > #268627 > unrolled thread
| Started by | Kamil Jońca <kjonca@o2.pl> |
|---|---|
| First post | 2024-03-29 19:30 +0100 |
| Last post | 2024-03-30 12:40 +0100 |
| Articles | 3 — 3 participants |
Back to article view | Back to linux.debian.user
This discussion starts older than the indexed window; earlier articles aren't shown. The article labeled Started by
below is the oldest one visible, not the original post.
Re: making Debian secure by default Kamil Jońca <kjonca@o2.pl> - 2024-03-29 19:30 +0100
Re: making Debian secure by default Andy Smith <andy@strugglers.net> - 2024-03-29 21:10 +0100
Re: making Debian secure by default Marc SCHAEFER <schaefer@alphanet.ch> - 2024-03-30 12:40 +0100
| From | Kamil Jońca <kjonca@o2.pl> |
|---|---|
| Date | 2024-03-29 19:30 +0100 |
| Subject | Re: making Debian secure by default |
| Message-ID | <Inp9f-2A8j-1@gated-at.bofh.it> |
Andy Smith <andy@strugglers.net> writes: [...] > https://www.openwall.com/lists/oss-security/2024/03/29/4 > > (Upstream xz/lzma project compromised, hostile code inserted into > sshd in Debian sid and other leading edge distros.) > > Thanks, > Andy O-o, is there any simple test to check if I have infected version or not? KJ -- http://wolnelektury.pl/wesprzyj/teraz/
[toc] | [next] | [standalone]
| From | Andy Smith <andy@strugglers.net> |
|---|---|
| Date | 2024-03-29 21:10 +0100 |
| Message-ID | <InqI1-2BdI-7@gated-at.bofh.it> |
| In reply to | #268627 |
Hello, On Fri, Mar 29, 2024 at 07:02:54PM +0100, Kamil Jońca wrote: > Andy Smith <andy@strugglers.net> writes: > > https://www.openwall.com/lists/oss-security/2024/03/29/4 > > > > (Upstream xz/lzma project compromised, hostile code inserted into > > sshd in Debian sid and other leading edge distros.) > > O-o, is there any simple test to check if I have infected version or > not? Reading the link fully would show you how, but as far as Debian ics concerned it only made it to testing and sid. If you run either of those then Debian's own security announcements cover it. Thanks, Andy -- https://bitfolk.com/ -- No-nonsense VPS hosting
[toc] | [prev] | [next] | [standalone]
| From | Marc SCHAEFER <schaefer@alphanet.ch> |
|---|---|
| Date | 2024-03-30 12:40 +0100 |
| Message-ID | <InFe1-2KkK-3@gated-at.bofh.it> |
| In reply to | #268627 |
Hello,
On Fri, Mar 29, 2024 at 07:02:54PM +0100, Kamil Jo?ca wrote:
> O-o, is there any simple test to check if I have infected version or
> not?
For example, under root:
path="$(ldd $(which sshd) | grep liblzma | grep -o '/[^ ]*')"
if hexdump -ve '1/1 "%.2x"' "$path" | grep -q f30f1efa554889f54c89ce5389fb81e7000000804883ec28488954241848894c2410
then
echo probably vulnerable
else
echo probably not vulnerable
fi
NB: always think and read before typing root commands, or any commands
you find on a forum or mailing-list :)
More info:
https://boehs.org/node/everything-i-know-about-the-xz-backdoor
Interesting read about social interactions
https://www.openwall.com/lists/oss-security/2024/03/29/4
ref for the code above
https://www.openwall.com/lists/oss-security/2024/03/29/23
idea to confine the sshd -> systemd dependancy,
in a specific process, because of the huge systemd
attack surface
[toc] | [prev] | [standalone]
Back to top | Article view | linux.debian.user
csiph-web