This was a highly targeted yet massively distributed backdoor. Only systems running the right Xz version with the right systemd/openssh config could be abused. Even then, the attacker had to use the right key at the right time in the right way. 1/3
Conversation
Notices
-
Embed this notice
Marc Rogers ? ?? ⚠️ (cj@chaos.social)'s status on Saturday, 06-Apr-2024 20:14:59 JST Marc Rogers ? ?? ⚠️ - clacke likes this.
-
Embed this notice
clacke (clacke@libranet.de)'s status on Saturday, 06-Apr-2024 20:15:07 JST clacke For anyone catching one of these posts out of context, the full thread is:
(chaos.social/@cj/1121994763443…)
chaos.social/@cj/1121994776042…
chaos.social/@cj/1121994788936…
chaos.social/@cj/1121994815399…