Search
Search titles only
By:
Search titles only
By:
Log in
Register
Search
Search titles only
By:
Search titles only
By:
Menu
Install the app
Install
Forums
New posts
All threads
Latest threads
New posts
Trending threads
Trending
Search forums
What's new
New posts
New ads
New profile posts
Latest activity
Free Ads
Latest reviews
Search ads
Members
Current visitors
New profile posts
Search profile posts
Contact us
Latest ads
Bodim.lk out now !
Manoj Suranga Bandara
Updated:
Yesterday at 3:05 AM
Power Lifting Lever Belt
SkullVamp
Updated:
Jun 13, 2026
Ad icon
port.lk Domain for sale
Lankan-Tech
Updated:
Jun 13, 2026
Colombo
Kaduwela - Two Storey House for Sale
dilrasan
Updated:
Jun 11, 2026
Ad icon
Wechat qr verification
Pawan2005
Updated:
Jun 11, 2026
Electronics
Vehicles
Property
Search
Reply to thread
Forums
General
ElaKiri Talk!
The XZ Hack...
Get the App
JavaScript is disabled. For a better experience, please enable JavaScript in your browser before proceeding.
You are using an out of date browser. It may not display this or other websites correctly.
You should upgrade or use an
alternative browser
.
Message
<blockquote data-quote="imhotep" data-source="post: 29718437" data-attributes="member: 562115"><p>Just a few days ago, a lone Microsoft developer rocked the world when he revealed a backdoor had been intentionally planted in xz Utils, an open source data compression utility available on almost all installations of Linux and other Unix-like operating systems. <strong>The person or people behind this project likely spent years on it</strong>. They were likely very close to seeing the backdoor update merged into Debian and Red Hat, the two biggest distributions of Linux, when an eagle-eyed software developer spotted something fishy.</p><p></p><p>xz Utils is nearly ubiquitous in Linux. It provides lossless data compression on virtually all Unix-like operating systems, including Linux. xz Utils provides critical functions for compressing and decompressing data during all kinds of operations. xz Utils also supports the legacy .lzma format, making this component even more crucial.</p><p></p><p>Andres Freund, a developer and engineer working on Microsoft’s PostgreSQL offerings, was recently troubleshooting performance problems a Debian system was experiencing with SSH, the most widely used protocol for remotely logging in to devices over the Internet. Specifically, SSH logins were consuming too many CPU cycles and were generating errors with valgrind, a utility for monitoring computer memory.</p><p></p><p>Through sheer luck and Freund’s careful eye, he eventually discovered the problems were the result of updates that had been made to xz Utils. On Friday, Freund took to the Open Source Security List to disclose the updates were the result of someone intentionally planting a backdoor in the compression software.</p><p></p><p>"This might be the best executed supply chain attack we've seen described in the open, and it's a nightmare scenario: malicious, competent, authorized upstream in a widely used library," software and cryptography engineer Filippo Valsorda said of the effort, which came frightfully close to succeeding.</p><p></p><p>For more info.....</p><p></p><p><a href="https://www.cisa.gov/news-events/alerts/2024/03/29/reported-supply-chain-compromise-affecting-xz-utils-data-compression-library-cve-2024-3094" target="_blank">CISA Alert</a></p><p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-3094" target="_blank">NIST CVE-2024-3094</a></p><p></p><p>More <a href="https://www.openwall.com/lists/oss-security/2024/03/29/4" target="_blank">Details by Andres Freund</a></p><p></p><p>The xz developers will release a clean XZ Utils version 5.8.0 soon. Some wish that it clearly separates the clean one from the bad 5.6.x.</p><p></p><p>It's reasonably sure the following things need to be true for your system to be vulnerable:</p><ul> <li data-xf-list-type="ul">You need to be running a distro that uses glibc (for IFUNC)</li> <li data-xf-list-type="ul">You need to have versions 5.6.0 or 5.6.1 of xz or liblzma installed (xz-utils provides the library liblzma) - likely only true if running a rolling-release distro and updating religiously.</li> </ul><p>It's known that the combination of <em>systemd</em> and <em>patched openssh</em> are vulnerable but pending further analysis of the payload, it cannot be certain that other configurations aren't.</p></blockquote><p></p>
[QUOTE="imhotep, post: 29718437, member: 562115"] Just a few days ago, a lone Microsoft developer rocked the world when he revealed a backdoor had been intentionally planted in xz Utils, an open source data compression utility available on almost all installations of Linux and other Unix-like operating systems. [B]The person or people behind this project likely spent years on it[/B]. They were likely very close to seeing the backdoor update merged into Debian and Red Hat, the two biggest distributions of Linux, when an eagle-eyed software developer spotted something fishy. xz Utils is nearly ubiquitous in Linux. It provides lossless data compression on virtually all Unix-like operating systems, including Linux. xz Utils provides critical functions for compressing and decompressing data during all kinds of operations. xz Utils also supports the legacy .lzma format, making this component even more crucial. Andres Freund, a developer and engineer working on Microsoft’s PostgreSQL offerings, was recently troubleshooting performance problems a Debian system was experiencing with SSH, the most widely used protocol for remotely logging in to devices over the Internet. Specifically, SSH logins were consuming too many CPU cycles and were generating errors with valgrind, a utility for monitoring computer memory. Through sheer luck and Freund’s careful eye, he eventually discovered the problems were the result of updates that had been made to xz Utils. On Friday, Freund took to the Open Source Security List to disclose the updates were the result of someone intentionally planting a backdoor in the compression software. "This might be the best executed supply chain attack we've seen described in the open, and it's a nightmare scenario: malicious, competent, authorized upstream in a widely used library," software and cryptography engineer Filippo Valsorda said of the effort, which came frightfully close to succeeding. For more info..... [URL='https://www.cisa.gov/news-events/alerts/2024/03/29/reported-supply-chain-compromise-affecting-xz-utils-data-compression-library-cve-2024-3094']CISA Alert[/URL] [URL='https://nvd.nist.gov/vuln/detail/CVE-2024-3094']NIST CVE-2024-3094[/URL] More [URL='https://www.openwall.com/lists/oss-security/2024/03/29/4']Details by Andres Freund[/URL] The xz developers will release a clean XZ Utils version 5.8.0 soon. Some wish that it clearly separates the clean one from the bad 5.6.x. It's reasonably sure the following things need to be true for your system to be vulnerable: [LIST] [*]You need to be running a distro that uses glibc (for IFUNC) [*]You need to have versions 5.6.0 or 5.6.1 of xz or liblzma installed (xz-utils provides the library liblzma) - likely only true if running a rolling-release distro and updating religiously. [/LIST] It's known that the combination of [I]systemd[/I] and [I]patched openssh[/I] are vulnerable but pending further analysis of the payload, it cannot be certain that other configurations aren't. [/QUOTE]
Insert quotes…
Verification
Dahaya deken beduwama keeyada?
Post reply
Top
Bottom