• Hi folks,

    the forum is now set to read only.

    After 6 yrs under my control, I have done all the work on April 6th that was needed to be able to transfer the database, forum files and the domain to Philipp Moeller aka @Phil7. The Github repository was already transfered and under his control.

    According to GDPR/DSGVO laws, all user accounts are now deleted that didn't accept the new terms (Updated on March 7th 2024 and an email was send to your address).

    I wish you all a great future and health. As the internet is gigantic but sometimes also very small, I am sure we will bump into each other someday again. Looking forward to it. :-)

    Cheers
    Michael

  • Hi folks,
    as per verbal aggreement between the new owner of the Cerberus X community and myself, I will keep this place online till May 6th, 2024.
    After that date it will be purged and this Domain will be most likely be used for my own stuff again.
    I am not participating in the new place for various reasons.
    If someone wants to contact me you can do so via mail to mike@fantomgl.com.
    Best wishes
    Michael

xz compression utils backdoor found. in Linux

dawlane

Well-known member
CX Code Contributor
Tutorial Author
Joined
Jun 21, 2017
Messages
1,147
If you don't already know by now. A backdoor was introduced into one of the main upstream repositories that every x86_64 Linux distribution relies on. It was only discovered by chance by some one working for Microsoft that noticed ssh logins were taking longer by a few milliseconds. They traced it down to the xz compression tool where the malicious code was very cleverly hidden in a test binary.

What is more surprising is how this backdoor got into the repository. It looks like author of this code actually managed to take over the upstream xz repository by social engineering, possibly by themselves or in collusion with others to get the original maintainer to give them access to do their own commits.

 
Back
Top Bottom