Adventures in Dystopia
Package : xz-utils CVE ID : CVE-2024-3094 Andres Freund discovered that the upstream source tarballs for xz-utils, the XZ-format compression utilities, are compromised and inject malicious code, at build time, into the resulting liblzma5 library.โฆ
https://github.com/amlweems/xzbot finally, after three days, fully reversed PoC
GitHub
GitHub - amlweems/xzbot: notes, honeypot, and exploit demo for the xz backdoor (CVE-2024-3094)
notes, honeypot, and exploit demo for the xz backdoor (CVE-2024-3094) - amlweems/xzbot
๐4
The NSA's stated objective was to "Collect it All," "Process it All," "Exploit it All," "Partner it All," "Sniff it All" and "Know it All."
(Source: footnote from leaked by Snowden internal slides)
(Source: footnote from leaked by Snowden internal slides)
Adventures in Dystopia
https://github.com/amlweems/xzbot finally, after three days, fully reversed PoC
Wana more lulz?
https://git.tukaani.org/?p=xz.git;a=log;pg=1 the attacker (-s) changed the UA versions of MAN pages. ;)
https://git.tukaani.org/?p=xz.git;a=log;pg=1 the attacker (-s) changed the UA versions of MAN pages. ;)
๐ค2