Sujet : Re: Malware find in the news: xz related.
De : jgd (at) *nospam* cix.co.uk (John Dallman)
Groupes : comp.os.linux.miscDate : 07. Apr 2024, 17:05:08
Autres entêtes
Organisation : A noiseless patient Spider
Message-ID : <memo.20240407170504.4708h@jgd.cix.co.uk>
References : 1
In article <
eplaekx4iu.ln2@Telcontar.valinor>,
robin_listas@es.invalid(Carlos E.R.) wrote:
On 2024-04-01 10:44, Marco Moock wrote:
Linux distributions with systemd are now the vast majority, so
maybe the author didn't care about some Gentoo or slackware machines.
Maybe they have certain machines in mind for attacking, and they
know what they run
The build script part of the attack activated when building .deb or .rpm
packages. If it had not been detected, it would have got into Debian
stable, and then into the vast array of derivatives, notably Ubuntu. It
would also have got into RHEL. That doesn't have direct downstreams any
more, but Rocky, Alma and Oracle follow its example in taking updated
packages, and Amazon Linux takes a fair bit of notice.
The combination of these targets would have compromised a large fraction
of the world's cloud servers. The problem for an intelligence agency
would have been finding the most interesting data, not in getting it.
John