April 20, 2024, 4:19 p.m. | pO0q 🦄

DEV Community dev.to

The recent attempt to compromise XZ, a library included in many Linux distributions out of the box, is worrying.





What's the point?


As far as I know, the attackers aimed to compromise the SSH daemon and ultimately expose vulnerable machines to the internet through SSH.


Any Linux machine running popular distributions, such as Ubuntu, would have been compromised:



Fortunately, it failed, but we're lucky, as the engineer who discovered the anomaly was not looking for security flaws.


Source: Openwall …

attackers backdoor box compromise daemon developer distributions expose far internet library linux linux distributions machine machines opensource point popular running security ssh threat ultimately vulnerable xz backdoor

Information Security Engineers

@ D. E. Shaw Research | New York City

Technology Security Analyst

@ Halton Region | Oakville, Ontario, Canada

Senior Cyber Security Analyst

@ Valley Water | San Jose, CA

Security Operations Manager-West Coast

@ The Walt Disney Company | USA - CA - 2500 Broadway Street

Vulnerability Analyst - Remote (WFH)

@ Cognitive Medical Systems | Phoenix, AZ, US | Oak Ridge, TN, US | Austin, TX, US | Oregon, US | Austin, TX, US

Senior Mainframe Security Administrator

@ Danske Bank | Copenhagen V, Denmark