Skip Navigation
InitialsDiceBearhttps://github.com/dicebear/dicebearhttps://creativecommons.org/publicdomain/zero/1.0/„Initials” (https://github.com/dicebear/dicebear) by „DiceBear”, licensed under „CC0 1.0” (https://creativecommons.org/publicdomain/zero/1.0/)EM
Posts
1
Comments
30
Joined
2 yr. ago
  • Yes, indeed the backdoor code checks, in the event of ssh authentication with a certificate, that it was signed with a specific ssh private key (their own CA), the corresponding public key being hardcoded in the backdoor code.

    But this project xzbot demonstrates how to patch the corrupted liblzma to replace the key

  • Oh thank you so much for these instructions I'll go through them on my computer.

    I indeed wanted to know if the versions were still downloadable anywhere but if you can still install the correct liblzma version on any version of the distribution that works. I tried on a Debian VM on mac but with too little knowledge and it never run the correct liblzma

    xzbot from Anthony Weems enables to patch the corrupted liblzma to change the private key used to compare it to the signed ssh certificate, so adding this to your instructions might enable me to demonstrate sshing into the VM :)

  • Linux @lemmy.ml
    emidio @lemmy.blahaj.zone

    Download xz Utils infected distro version

    Hi ! I want to demo the backdoor usage and would like to install a unstable/test version of a distribution (possibly Debian or Fedora) that had the backdoor (v5.6.0 or 5.6.1 of xz/liblzma and patched openssh for systemd notification)

    How could I do that?

    I will be using xzbot from amlweems to further patch liblzma but I want a distro that has openssh run by systemd that links to the correct liblzma version

    Thank you!

  • Where are the tanks in Ukraine? Well there are tanks and other heavy weapons from all western countries in Ukraine and part of Russia. It's not Uktaines' war. The territory were already under Russian influence and population. This is classic US vs Russia, NATO vs BRICs