April 4, 2024, 5:32 p.m. | /u/MartinZugec

cybersecurity www.reddit.com

Hey everyone,



Just wanted to share a new tool we developed to help identify XZ backdoor vulnerability (CVE-2024-3094).



\- Standalone & Portable: No additional software needed, runs on various Linux systems (written in Go)

\- Two Scanning Modes: Choose between Fast Scan and Full Scan (--system)



Important Notes:

\- Requires root privileges to run effectively.

\- Initial testing on Fedora, Debian, but wider testing is recommended.

\- Identifies vulnerable liblzma versions and searches for the backdoor's malicious code.



How to …

amp backdoor cve cve-2024 cve-2024-3094 cybersecurity effectively fast hey identify important linux linux systems portable privileges root run scan scanner scanning share software system systems tool vulnerability written xz backdoor

CyberSOC Technical Lead

@ Integrity360 | Sandyford, Dublin, Ireland

Cyber Security Strategy Consultant

@ Capco | New York City

Cyber Security Senior Consultant

@ Capco | Chicago, IL

Sr. Product Manager

@ MixMode | Remote, US

Security Compliance Strategist

@ Grab | Petaling Jaya, Malaysia

Cloud Security Architect, Lead

@ Booz Allen Hamilton | USA, VA, McLean (1500 Tysons McLean Dr)