{"id":12559,"date":"2024-04-03T05:42:24","date_gmt":"2024-04-03T05:42:24","guid":{"rendered":"https:\/\/demo4.dedicatedhost247.com\/newstime\/how-one-volunteer-stopped-a-backdoor-from-exposing-linux-systems-worldwide\/"},"modified":"2024-04-03T05:42:24","modified_gmt":"2024-04-03T05:42:24","slug":"how-one-volunteer-stopped-a-backdoor-from-exposing-linux-systems-worldwide","status":"publish","type":"post","link":"https:\/\/demo4.dedicatedhost247.com\/newstime\/how-one-volunteer-stopped-a-backdoor-from-exposing-linux-systems-worldwide\/","title":{"rendered":"How one volunteer stopped a backdoor from exposing Linux systems worldwide"},"content":{"rendered":"<p> <br \/>\n<\/p>\n<div>\n<div class=\"duet--article--article-body-component\">\n<p class=\"duet--article--dangerously-set-cms-markup duet--article--standard-paragraph mb-20 font-fkroman text-18 leading-160 -tracking-1 selection:bg-franklin-20 dark:text-white dark:selection:bg-blurple [&amp;_a:hover]:shadow-highlight-franklin dark:[&amp;_a:hover]:shadow-highlight-blurple [&amp;_a]:shadow-underline-black dark:[&amp;_a]:shadow-underline-white\">Linux, the most widely used open source operating system in the world, narrowly escaped a massive cyber attack over Easter weekend, all thanks to one volunteer.<\/p>\n<\/div>\n<div class=\"duet--article--article-body-component\">\n<p class=\"duet--article--dangerously-set-cms-markup duet--article--standard-paragraph mb-20 font-fkroman text-18 leading-160 -tracking-1 selection:bg-franklin-20 dark:text-white dark:selection:bg-blurple [&amp;_a:hover]:shadow-highlight-franklin dark:[&amp;_a:hover]:shadow-highlight-blurple [&amp;_a]:shadow-underline-black dark:[&amp;_a]:shadow-underline-white\">The backdoor had been inserted into a recent release of a Linux compression format called XZ Utils, a tool that is little-known outside the Linux world but is used in nearly every Linux distribution to compresses large files, making them easier to transfer. If it had spread more widely, an untold number of systems could have been left compromised for years.<\/p>\n<\/div>\n<div class=\"duet--article--article-body-component\">\n<p class=\"duet--article--dangerously-set-cms-markup duet--article--standard-paragraph mb-20 font-fkroman text-18 leading-160 -tracking-1 selection:bg-franklin-20 dark:text-white dark:selection:bg-blurple [&amp;_a:hover]:shadow-highlight-franklin dark:[&amp;_a:hover]:shadow-highlight-blurple [&amp;_a]:shadow-underline-black dark:[&amp;_a]:shadow-underline-white\">And as <em>Ars Technica<\/em> noted in its <a href=\"https:\/\/arstechnica.com\/security\/2024\/03\/backdoor-found-in-widely-used-linux-utility-breaks-encrypted-ssh-connections\/\">exhaustive recap<\/a>, the culprit had been working on the project out in the open.<\/p>\n<\/div>\n<div class=\"duet--article--article-body-component\">\n<p class=\"duet--article--dangerously-set-cms-markup duet--article--standard-paragraph mb-20 font-fkroman text-18 leading-160 -tracking-1 selection:bg-franklin-20 dark:text-white dark:selection:bg-blurple [&amp;_a:hover]:shadow-highlight-franklin dark:[&amp;_a:hover]:shadow-highlight-blurple [&amp;_a]:shadow-underline-black dark:[&amp;_a]:shadow-underline-white\">The vulnerability, inserted into Linux\u2019s remote log-in, only exposed itself to a single key, so that it could hide from scans of public computers. As <a href=\"https:\/\/stratechery.com\/2024\/the-xz-backdoor-what-happened-open-source-safety\/\">Ben Thompson writes in <em>Stratechery<\/em><\/a>.\u00a0 \u201cthe majority of the world\u2019s computers would be vulnerable and no one would know.\u201d<\/p>\n<\/div>\n<div class=\"duet--article--article-body-component\">\n<p class=\"duet--article--dangerously-set-cms-markup duet--article--standard-paragraph mb-20 font-fkroman text-18 leading-160 -tracking-1 selection:bg-franklin-20 dark:text-white dark:selection:bg-blurple [&amp;_a:hover]:shadow-highlight-franklin dark:[&amp;_a:hover]:shadow-highlight-blurple [&amp;_a]:shadow-underline-black dark:[&amp;_a]:shadow-underline-white\">The story of the XZ backdoor\u2019s discovery starts in the early morning of March 29th, as San Francisco-based Microsoft developer Andres Freund posted on Mastodon and <a href=\"https:\/\/www.openwall.com\/lists\/oss-security\/2024\/03\/29\/4\">sent an email<\/a> to OpenWall\u2019s security mailing list with the heading: \u201cbackdoor in upstream xz\/liblzma leading to ssh server compromise.\u201d <\/p>\n<\/div>\n<div class=\"duet--article--article-body-component\">\n<p class=\"duet--article--dangerously-set-cms-markup duet--article--standard-paragraph mb-20 font-fkroman text-18 leading-160 -tracking-1 selection:bg-franklin-20 dark:text-white dark:selection:bg-blurple [&amp;_a:hover]:shadow-highlight-franklin dark:[&amp;_a:hover]:shadow-highlight-blurple [&amp;_a]:shadow-underline-black dark:[&amp;_a]:shadow-underline-white\">Freund, who volunteers as a \u201cmaintainer\u201d for PostgreSQL, a Linux-based database, noticed a few strange things over the past few weeks while running tests. Encrypted log-ins to liblzma, part of the XZ compression library, were using up a ton of CPU. None of the performance tools he used revealed anything, Freund wrote on Mastodon. This immediately made him suspicious, and he remembered an \u201codd complaint\u201d from a Postgres user a couple of weeks earlier about Valgrind, Linux\u2019s program that checks for memory errors.\u00a0<\/p>\n<\/div>\n<div class=\"duet--article--article-body-component\">\n<p class=\"duet--article--dangerously-set-cms-markup duet--article--standard-paragraph mb-20 font-fkroman text-18 leading-160 -tracking-1 selection:bg-franklin-20 dark:text-white dark:selection:bg-blurple [&amp;_a:hover]:shadow-highlight-franklin dark:[&amp;_a:hover]:shadow-highlight-blurple [&amp;_a]:shadow-underline-black dark:[&amp;_a]:shadow-underline-white\">After some sleuthing, Freund eventually discovered what was wrong. \u201cThe upstream xz repository and the xz tarballs have been backdoored,\u201d noted Freund in his email. The malicious code was in versions \u200b\u200b5.6.0 and 5.6.1 of the xz tools and libraries.\u00a0<\/p>\n<\/div>\n<div class=\"duet--article--article-body-component\">\n<p class=\"duet--article--dangerously-set-cms-markup duet--article--standard-paragraph mb-20 font-fkroman text-18 leading-160 -tracking-1 selection:bg-franklin-20 dark:text-white dark:selection:bg-blurple [&amp;_a:hover]:shadow-highlight-franklin dark:[&amp;_a:hover]:shadow-highlight-blurple [&amp;_a]:shadow-underline-black dark:[&amp;_a]:shadow-underline-white\">Shortly after, enterprise opensource software company Red Hat sent out an <a href=\"https:\/\/www.redhat.com\/en\/blog\/urgent-security-alert-fedora-41-and-rawhide-users\">emergency security alert<\/a> for users of Fedora Rawhide and Fedora Linux 40. Ultimately, the company concluded that the beta version of Fedora Linux 40 contained two affected versions of the xz libraries. Fedora Rawhide versions likely received versions 5.6.0 or 5.6.1 as well. <\/p>\n<\/div>\n<div class=\"duet--article--article-body-component\">\n<blockquote class=\"duet--article--blockquote jzbdts2\">\n<p class=\"duet--article--dangerously-set-cms-markup jzbdtsa jzbdts0\">PLEASE IMMEDIATELY STOP USAGE OF ANY FEDORA RAWHIDE INSTANCES for work or personal activity. Fedora Rawhide will be reverted to xz-5.4.x shortly, and once that is done, Fedora Rawhide instances can safely be redeployed.<\/p>\n<\/blockquote>\n<\/div>\n<div class=\"duet--article--article-body-component\">\n<p class=\"duet--article--dangerously-set-cms-markup duet--article--standard-paragraph mb-20 font-fkroman text-18 leading-160 -tracking-1 selection:bg-franklin-20 dark:text-white dark:selection:bg-blurple [&amp;_a:hover]:shadow-highlight-franklin dark:[&amp;_a:hover]:shadow-highlight-blurple [&amp;_a]:shadow-underline-black dark:[&amp;_a]:shadow-underline-white\">Although a beta version of Debian, the free Linux distribution, contained compromised packages, its security team <a href=\"https:\/\/lists.debian.org\/debian-security-announce\/2024\/msg00057.html\">acted swiftly<\/a> to revert them. \u201cRight now no Debian stable versions are known to be affected,\u201d wrote Debian\u2019s Salvatore Bonaccorso in a security alert to users on Friday evening. <\/p>\n<\/div>\n<div class=\"duet--article--article-body-component\">\n<p class=\"duet--article--dangerously-set-cms-markup duet--article--standard-paragraph mb-20 font-fkroman text-18 leading-160 -tracking-1 selection:bg-franklin-20 dark:text-white dark:selection:bg-blurple [&amp;_a:hover]:shadow-highlight-franklin dark:[&amp;_a:hover]:shadow-highlight-blurple [&amp;_a]:shadow-underline-black dark:[&amp;_a]:shadow-underline-white\">Freund later identified the person who submitted the malicious code as one of two main xz Utils developers, known as JiaT75, or Jia Tan. \u201cGiven the activity over several weeks, the committer is either directly involved or there was some quite severe compromise of their system. Unfortunately the latter looks like the less likely explanation, given they communicated on various lists about the \u201cfixes\u201d mentioned above,\u201d wrote Freund in his <a href=\"https:\/\/seclists.org\/oss-sec\/2024\/q1\/268\">analysis<\/a>, after linking several workarounds that were made by JiaT75. <\/p>\n<\/div>\n<div class=\"duet--article--article-body-component\">\n<p class=\"duet--article--dangerously-set-cms-markup duet--article--standard-paragraph mb-20 font-fkroman text-18 leading-160 -tracking-1 selection:bg-franklin-20 dark:text-white dark:selection:bg-blurple [&amp;_a:hover]:shadow-highlight-franklin dark:[&amp;_a:hover]:shadow-highlight-blurple [&amp;_a]:shadow-underline-black dark:[&amp;_a]:shadow-underline-white\">JiaT75 was a familiar name: they\u2019d worked side-by-side with the original developer of .xz file format, Lasse Collin, for a while. As programmer Russ Cox noted in his <a href=\"https:\/\/research.swtch.com\/xz-timeline\">timeline<\/a>, JiaT75 started by sending apparently legitimate patches to the XZ mailing list in October of 2021. <\/p>\n<\/div>\n<div class=\"duet--article--article-body-component\">\n<p class=\"duet--article--dangerously-set-cms-markup duet--article--standard-paragraph mb-20 font-fkroman text-18 leading-160 -tracking-1 selection:bg-franklin-20 dark:text-white dark:selection:bg-blurple [&amp;_a:hover]:shadow-highlight-franklin dark:[&amp;_a:hover]:shadow-highlight-blurple [&amp;_a]:shadow-underline-black dark:[&amp;_a]:shadow-underline-white\">Other arms of the scheme unfolded a few months later, as two other identities, Jigar Kumar and Dennis Ens, <a href=\"https:\/\/www.mail-archive.com\/xz-devel@tukaani.org\/\">began emailing complaints<\/a> to Collin about bugs and the project\u2019s slow development. However, as noted in reports by <a href=\"https:\/\/boehs.org\/node\/everything-i-know-about-the-xz-backdoor\">Evan Boehs<\/a> and others, \u201cKumar\u201d and \u201cEns\u201d were never seen outside the XZ community, leading investigators to believe both are fakes that existed only to help Jia Tan get into position to deliver the backdoored code.<\/p>\n<\/div>\n<div class=\"duet--article--article-body-component clear-both block\">\n<div class=\"my-9\">\n<div class=\"duet--media--caption pt-6 font-polysans-mono text-12 font-light leading-130 tracking-1\"><figcaption class=\"duet--article--dangerously-set-cms-markup inline text-gray-13 dark:text-gray-e9 [&amp;&gt;a:hover]:text-black [&amp;&gt;a:hover]:shadow-underline-black dark:[&amp;&gt;a:hover]:text-gray-e9 dark:[&amp;&gt;a:hover]:shadow-underline-gray-63 [&amp;&gt;a]:shadow-underline-gray-13 dark:[&amp;&gt;a]:shadow-underline-gray-63\"><em>An email from \u201cJigar Kumar\u201d pressuring the developer of XZ Utils to relinquish control of the project.<\/em><\/figcaption><cite class=\"duet--article--dangerously-set-cms-markup inline not-italic text-gray-63 dark:text-gray-bd [&amp;&gt;a:hover]:text-gray-63 [&amp;&gt;a:hover]:shadow-underline-black dark:[&amp;&gt;a:hover]:text-gray-bd dark:[&amp;&gt;a:hover]:shadow-underline-gray [&amp;&gt;a]:shadow-underline-gray-63 dark:[&amp;&gt;a]:text-gray-bd dark:[&amp;&gt;a]:shadow-underline-gray\">Image: Screenshot from <a href=\"https:\/\/www.mail-archive.com\/xz-devel@tukaani.org\/msg00568.html\">The Mail Archive<\/a><\/cite><\/div>\n<\/div>\n<\/div>\n<div class=\"duet--article--article-body-component\">\n<p class=\"duet--article--dangerously-set-cms-markup duet--article--standard-paragraph mb-20 font-fkroman text-18 leading-160 -tracking-1 selection:bg-franklin-20 dark:text-white dark:selection:bg-blurple [&amp;_a:hover]:shadow-highlight-franklin dark:[&amp;_a:hover]:shadow-highlight-blurple [&amp;_a]:shadow-underline-black dark:[&amp;_a]:shadow-underline-white\">\u201cI am sorry about your mental health issues, but its important to be aware of your own limits. I get that this is a hobby project for all contributors, but the community desires more,\u201d wrote Ens in one message, while Kumar said in another that \u201cProgress will not happen until there is new maintainer.\u201d<\/p>\n<\/div>\n<div class=\"duet--article--article-body-component\">\n<p class=\"duet--article--dangerously-set-cms-markup duet--article--standard-paragraph mb-20 font-fkroman text-18 leading-160 -tracking-1 selection:bg-franklin-20 dark:text-white dark:selection:bg-blurple [&amp;_a:hover]:shadow-highlight-franklin dark:[&amp;_a:hover]:shadow-highlight-blurple [&amp;_a]:shadow-underline-black dark:[&amp;_a]:shadow-underline-white\">In the midst of this back and forth, Collins wrote that \u201cI haven\u2019t lost interest but my ability to care has been fairly limited mostly due to longterm mental health issues but also due to some other things,\u201d and suggested Jia Tan would take on a bigger role. \u201cIt\u2019s also good to keep in mind that this is an unpaid hobby project,\u201d he concluded. The emails from \u201cKumar\u201d and \u201cEns\u201d continued until Tan was added as a maintainer later that year, able to make alterations, and attempt to get the backdoored package into Linux distributions with more authority.<\/p>\n<\/div>\n<div class=\"duet--article--article-body-component\">\n<p class=\"duet--article--dangerously-set-cms-markup duet--article--standard-paragraph mb-20 font-fkroman text-18 leading-160 -tracking-1 selection:bg-franklin-20 dark:text-white dark:selection:bg-blurple [&amp;_a:hover]:shadow-highlight-franklin dark:[&amp;_a:hover]:shadow-highlight-blurple [&amp;_a]:shadow-underline-black dark:[&amp;_a]:shadow-underline-white\">The xz backdoor incident and its aftermath are an example of both the beauty of open source and a striking vulnerability in the internet\u2019s infrastructure.<\/p>\n<\/div>\n<div class=\"duet--article--article-body-component\">\n<p class=\"duet--article--dangerously-set-cms-markup duet--article--standard-paragraph mb-20 font-fkroman text-18 leading-160 -tracking-1 selection:bg-franklin-20 dark:text-white dark:selection:bg-blurple [&amp;_a:hover]:shadow-highlight-franklin dark:[&amp;_a:hover]:shadow-highlight-blurple [&amp;_a]:shadow-underline-black dark:[&amp;_a]:shadow-underline-white\">A developer behind FFmpeg, a popular open-source media package, highlighted the problem <a href=\"https:\/\/twitter.com\/FFmpeg\/status\/1775178803129602500\">in a tweet<\/a>, saying \u201cThe xz fiasco has shown how a dependence on unpaid volunteers can cause major problems. Trillion dollar corporations expect free and urgent support from volunteers.\u201d And they brought receipts, pointing out how they dealt with a \u201chigh priority\u201d bug affecting Microsoft Teams.<\/p>\n<\/div>\n<div class=\"duet--article--article-body-component\">\n<p class=\"duet--article--dangerously-set-cms-markup duet--article--standard-paragraph mb-20 font-fkroman text-18 leading-160 -tracking-1 selection:bg-franklin-20 dark:text-white dark:selection:bg-blurple [&amp;_a:hover]:shadow-highlight-franklin dark:[&amp;_a:hover]:shadow-highlight-blurple [&amp;_a]:shadow-underline-black dark:[&amp;_a]:shadow-underline-white\">Despite Microsoft\u2019s dependence on its software, the developer writes, \u201cAfter politely requesting a support contract from Microsoft for long term maintenance, they offered a one-time payment of a few thousand dollars instead&#8230;investments in maintenance and sustainability are unsexy and probably won\u2019t get a middle manager their promotion but pay off a thousandfold over many years.\u201d  <\/p>\n<\/div>\n<div class=\"duet--article--article-body-component\">\n<p class=\"duet--article--dangerously-set-cms-markup duet--article--standard-paragraph mb-20 font-fkroman text-18 leading-160 -tracking-1 selection:bg-franklin-20 dark:text-white dark:selection:bg-blurple [&amp;_a:hover]:shadow-highlight-franklin dark:[&amp;_a:hover]:shadow-highlight-blurple [&amp;_a]:shadow-underline-black dark:[&amp;_a]:shadow-underline-white\">Details of who is behind \u201cJiaT75,\u201d how they executed their plan, and the extent of the damage are being unearthed by an army of developers and cybersecurity professionals, both on social media and online forums. But that happens without direct financial support from many of the companies and organizations who benefit from being able to use secure software.<\/p>\n<\/div>\n<\/div>\n<p><script async src=\"https:\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script><br \/>\n<br \/><br \/>\n<br \/><a href=\"https:\/\/www.theverge.com\/2024\/4\/2\/24119342\/xz-utils-linux-backdoor-attempt\">Source link <\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Linux, the most widely used open source operating system in the world, narrowly escaped a massive cyber attack over Easter<\/p>\n","protected":false},"author":1,"featured_media":11195,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":[],"categories":[2],"tags":[],"_links":{"self":[{"href":"https:\/\/demo4.dedicatedhost247.com\/newstime\/wp-json\/wp\/v2\/posts\/12559"}],"collection":[{"href":"https:\/\/demo4.dedicatedhost247.com\/newstime\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/demo4.dedicatedhost247.com\/newstime\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/demo4.dedicatedhost247.com\/newstime\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/demo4.dedicatedhost247.com\/newstime\/wp-json\/wp\/v2\/comments?post=12559"}],"version-history":[{"count":0,"href":"https:\/\/demo4.dedicatedhost247.com\/newstime\/wp-json\/wp\/v2\/posts\/12559\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/demo4.dedicatedhost247.com\/newstime\/wp-json\/wp\/v2\/media\/11195"}],"wp:attachment":[{"href":"https:\/\/demo4.dedicatedhost247.com\/newstime\/wp-json\/wp\/v2\/media?parent=12559"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/demo4.dedicatedhost247.com\/newstime\/wp-json\/wp\/v2\/categories?post=12559"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/demo4.dedicatedhost247.com\/newstime\/wp-json\/wp\/v2\/tags?post=12559"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}