Untitled attachment
https://cyberplace.social/system/media_attachments/files/112/197/989/630/093/579/original/5eadd2f1ee7b6760.png
.@amlw wrote a great proof of concept for #XZ to allow code execution via ssh.
Very important note: it doesn’t work in the wild as you need the private key, which only the threat actor(s) have. But you can create your own for exploiting your own servers.
GNU social JP is a social network, courtesy of GNU social JP管理人. It runs on GNU social, version 2.0.2-dev, available under the GNU Affero General Public License.
All GNU social JP content and data are available under the Creative Commons Attribution 3.0 license.