GNU social JP
  • FAQ
  • Login
GNU social JPは日本のGNU socialサーバーです。
Usage/ToS/admin/test/Pleroma FE
  • Public

    • Public
    • Network
    • Groups
    • Featured
    • Popular
    • People

Conversation

Notices

  1. Embed this notice
    Kevin Beaumont (gossithedog@cyberplace.social)'s status on Saturday, 30-Mar-2024 02:03:32 JST Kevin Beaumont Kevin Beaumont
    • Will Dormann

    HT to @wdormann here - somebody has backdoored the open source project XZ which has downstream impacts.

    For example, although OpenSSH doesn’t use XZ, Debian patch OpenSSH and introduced a dependency which translates as the XZ changes introducing a sshd authentication bypass backdoor it appears.

    One dude bothered to investigate in his free time about why ssh was running slow, so it was caught fairly early - i.e. hopefully before distros started bundling it.

    https://www.openwall.com/lists/oss-security/2024/03/29/4

    In conversation Saturday, 30-Mar-2024 02:03:32 JST from cyberplace.social permalink

    Attachments

    1. Domain not in remote thumbnail source whitelist: www.openwall.com
      oss-security - backdoor in upstream xz/liblzma leading to ssh server compromise
    • Embed this notice
      Kevin Beaumont (gossithedog@cyberplace.social)'s status on Saturday, 30-Mar-2024 02:14:15 JST Kevin Beaumont Kevin Beaumont
      in reply to

      Worryingly it looks like the backdoor comes via one of the two main devs and dates back over a month from their GitHub account, with legit commits too - XZ is used in systemd so this one might play out for a while.

      In conversation Saturday, 30-Mar-2024 02:14:15 JST permalink
    • Embed this notice
      Kevin Beaumont (gossithedog@cyberplace.social)'s status on Saturday, 30-Mar-2024 02:28:56 JST Kevin Beaumont Kevin Beaumont
      in reply to

      I suspect distros probably want to roll XZ back to around January 2024, stop bundling updates until the developer is removed in GitHub or a logical explanation can be given, and somebody needs to fund a code review of it.

      In conversation Saturday, 30-Mar-2024 02:28:56 JST permalink
    • Embed this notice
      Kevin Beaumont (gossithedog@cyberplace.social)'s status on Saturday, 30-Mar-2024 02:59:43 JST Kevin Beaumont Kevin Beaumont
      in reply to

      Here we go: https://www.bleepingcomputer.com/news/security/red-hat-warns-of-backdoor-in-xz-tools-used-by-most-linux-distros/

      As I said, the impact here will be very limited due to how quick it was caught. Everybody owes the finder a beer.

      In conversation Saturday, 30-Mar-2024 02:59:43 JST permalink

      Attachments


    • Embed this notice
      Kevin Beaumont (gossithedog@cyberplace.social)'s status on Saturday, 30-Mar-2024 05:28:33 JST Kevin Beaumont Kevin Beaumont
      in reply to
      • AndresFreundTec

      Postgre developer @AndresFreundTec saving Linux security from backdoors as a side of desk activity

      In conversation Saturday, 30-Mar-2024 05:28:33 JST permalink

      Attachments


    • Embed this notice
      Kevin Beaumont (gossithedog@cyberplace.social)'s status on Saturday, 30-Mar-2024 06:10:49 JST Kevin Beaumont Kevin Beaumont
      in reply to

      CISA advisory: Reported Supply Chain Compromise Affecting XZ Utils Data Compression Library, CVE-2024-3094 https://www.cisa.gov/news-events/alerts/2024/03/29/reported-supply-chain-compromise-affecting-xz-utils-data-compression-library-cve-2024-3094

      In conversation Saturday, 30-Mar-2024 06:10:49 JST permalink

      Attachments

      1. No result found on File_thumbnail lookup.
        Reported Supply Chain Compromise Affecting XZ Utils Data Compression Library, CVE-2024-3094 | CISA
    • Embed this notice
      Kevin Beaumont (gossithedog@cyberplace.social)'s status on Saturday, 30-Mar-2024 06:20:49 JST Kevin Beaumont Kevin Beaumont
      in reply to

      The person/account on XZ repo also altered the security disclosure policy on that and other repos they author in months prior.

      In conversation Saturday, 30-Mar-2024 06:20:49 JST permalink
    • Embed this notice
      Kevin Beaumont (gossithedog@cyberplace.social)'s status on Saturday, 30-Mar-2024 08:00:31 JST Kevin Beaumont Kevin Beaumont
      in reply to

      Interesting find by @fuomag9 - the XZ repo person tried getting Ubuntu to update yesterday by filing a bug report https://bugs.launchpad.net/bugs/2059417

      In conversation Saturday, 30-Mar-2024 08:00:31 JST permalink

      Attachments

      1. Domain not in remote thumbnail source whitelist: bugs.launchpad.net
        Bug #2059417 “Sync xz-utils 5.6.1-1 (main) from Debian unstable ...” : Bugs : xz-utils package : Ubuntu
        Please sync xz-utils 5.6.1-1 (main) from Debian unstable (main) Hello! I am one of the upstream maintainers for XZ Utils. Version 5.6.1 was recently released and uploaded to Debian as a bugfix only release. Notably, this fixes a bug that causes Valgrind to issue a warning on any application dynamically linked with liblzma. This includes a lot of important applications. This could break build scripts and test pipelines that expect specific output from Valgrind in order to pass. Additionally,...
      Haelwenn /элвэн/ :triskell: likes this.
      Haelwenn /элвэн/ :triskell: repeated this.
    • Embed this notice
      Kevin Beaumont (gossithedog@cyberplace.social)'s status on Saturday, 30-Mar-2024 08:28:31 JST Kevin Beaumont Kevin Beaumont
      in reply to

      The Twilight zone time - a bug from 2015 comes back around in XZ incident, it appears https://github.com/google/sanitizers/issues/342

      In conversation Saturday, 30-Mar-2024 08:28:31 JST permalink

      Attachments

      1. Domain not in remote thumbnail source whitelist: opengraph.githubassets.com
        Segfault in instrumented programs that use GNU indirect functions. · Issue #342 · google/sanitizers
        Originally reported on Google Code with ID 342 What steps will reproduce the problem? 1. Testcase is attached. Compile with GCC with -fsanitize=address option. 2. Run. 3. What is the expected outpu...
      Haelwenn /элвэн/ :triskell: likes this.
    • Embed this notice
      Kevin Beaumont (gossithedog@cyberplace.social)'s status on Saturday, 30-Mar-2024 17:30:05 JST Kevin Beaumont Kevin Beaumont
      in reply to

      Multiple different XZ repos and website have been suspended by GitHub.

      In conversation Saturday, 30-Mar-2024 17:30:05 JST permalink

      Attachments


      1. https://cyberplace.social/system/media_attachments/files/112/183/694/148/666/081/original/c25411a2ab632f73.png

      2. https://cyberplace.social/system/media_attachments/files/112/183/695/152/962/554/original/6dae9498d8c93a95.png

      3. https://cyberplace.social/system/media_attachments/files/112/183/695/465/388/345/original/62fe15a9585356c9.png

      4. https://cyberplace.social/system/media_attachments/files/112/183/695/967/591/697/original/b0fce52b13a193c5.png
    • Embed this notice
      Kevin Beaumont (gossithedog@cyberplace.social)'s status on Saturday, 30-Mar-2024 17:39:53 JST Kevin Beaumont Kevin Beaumont
      in reply to

      Back in 2022 a host of characters appeared and basically bullied the creator of the XZ project to hand it over to somebody else - at the time the guy cited mental health issues around not updating the project quickly.

      At the time he was already talking about maybe handing over to the account who years later introduced the backdoor.

      In mid 2023 said account introduced a change to Google’s OSS Fuzzer to weaken detection for XZ.

      Somebody played a years long game of Jenga and lost.

      In conversation Saturday, 30-Mar-2024 17:39:53 JST permalink
    • Embed this notice
      Kevin Beaumont (gossithedog@cyberplace.social)'s status on Saturday, 30-Mar-2024 17:46:58 JST Kevin Beaumont Kevin Beaumont
      in reply to

      Before everybody high fives each other, this is how the backdoor was found: somebody happened to look at why CPU usage had increased in sshd, and did all the research and notification work themselves. By this point the backdoor had been there for a month unnoticed.

      https://mastodon.social/@AndresFreundTec/112180406142695845

      I’ve made the joke before that if GCHQ aren’t introducing backdoors and vulns in open source that I want a tax refund. It wasn’t a joke. And it won’t be just be GCHQ.

      In conversation Saturday, 30-Mar-2024 17:46:58 JST permalink

      Attachments

      1. No result found on File_thumbnail lookup.
        AndresFreundTec (@AndresFreundTec@mastodon.social)
        from AndresFreundTec
        I was doing some micro-benchmarking at the time, needed to quiesce the system to reduce noise. Saw sshd processes were using a surprising amount of CPU, despite immediately failing because of wrong usernames etc. Profiled sshd, showing lots of cpu time in liblzma, with perf unable to attribute it to a symbol. Got suspicious. Recalled that I had seen an odd valgrind complaint in automated testing of postgres, a few weeks earlier, after package updates. Really required a lot of coincidences.
    • Embed this notice
      Khleedril (khleedril@cyberplace.social)'s status on Saturday, 30-Mar-2024 18:47:56 JST Khleedril Khleedril
      in reply to

      @GossiTheDog I'm sure the finder is basking in kudos right now! Good on them.

      In conversation Saturday, 30-Mar-2024 18:47:56 JST permalink
    • Embed this notice
      maswan (maswan@mastodon.acc.sunet.se)'s status on Saturday, 30-Mar-2024 19:16:43 JST maswan maswan
      in reply to

      @GossiTheDog
      One could argue that your tax money should also be spent by GCHQ to happen to look into increased CPU usage after some weird lib update in all the places where they didn't plant anything.

      In conversation Saturday, 30-Mar-2024 19:16:43 JST permalink
    • Embed this notice
      maswan (maswan@mastodon.acc.sunet.se)'s status on Saturday, 30-Mar-2024 19:26:57 JST maswan maswan

      @GossiTheDog
      Denying foreign actors access to UK companies secrets isn't in under economic advantage?

      Ours actually has that in there (especially for govt entities and suppliers), as does (theoretically) NSA.

      In conversation Saturday, 30-Mar-2024 19:26:57 JST permalink

Feeds

  • Activity Streams
  • RSS 2.0
  • Atom
  • Help
  • About
  • FAQ
  • TOS
  • Privacy
  • Source
  • Version
  • Contact

GNU social JP is a social network, courtesy of GNU social JP管理人. It runs on GNU social, version 2.0.2-dev, available under the GNU Affero General Public License.

Creative Commons Attribution 3.0 All GNU social JP content and data are available under the Creative Commons Attribution 3.0 license.