22 ms·
The Linux backdoor attempt of 2003 (2013)
- zhan_eg 3y agoPrevious discussions - [1] [2] [1] https://news.ycombinator.com/item?id=24106213 https://news.ycombinator.com/item?id=24106213 [2] https://news.ycombinator.com/item?id=18173173 https://news.ycombinator.com/item?id=18173173
- dang 3y agoThanks! Macroexpanded: The Linux Backdoor Attempt of 2003 (2013) - https://news.ycombinator.com/item?id=24106213 https://news.ycombinator.com/item?id=24106213 - Aug 2020 (141 comments) The Linux Backdoor Attempt of 2003 - https://news.ycombinator.com/item?id=18173173 https://news.ycombinator.com/item?id=18173173 - Oct 2018 (28 comments) The Linux Backdoor Attempt of 2003 - https://news.ycombinator.com/item?id=6520678 https://news.ycombinator.com/item?id=6520678 - Oct 2013 (63 comments)
- grugq 3y agoI have the full story on that incident. It is actually really funny. If the guy who did it wants to come forward, that is his decision. [edit: I won't name names.] He did provided me the full story. He told me with the understanding that the story would go public, so I will dig it up and post it. I also interviewed the sysadmins who were running the box at the time. 1. it was not an NSA operation, it was done by a hacker. 2. it was discovered by accident, not because of clever due diligence. Basically, there was a developer who had a flakey connection and one time his commits didn't go through. To detect this in future he had a script that would download the entire tree from the server and compare it against his local copy to make sure that his changes had been committed. It was discovered because of the discrepancy between his local working copy and the upstream copy. Which was checked not for security reasons, but because sometimes the two were out of sync. That's all. Just dumb luck. The sysadmins are still quite bitter about it. I know how it feels when your box is hacked and you really take it personally. The code wasn't added by hacking the CVS, as far as I remember, but rather through a hacked developer with commit rights. that's the story as I was told
- causal 3y agoWait was the guy you know the hacker or someone who discovered the hack by accident? If the latter, how do you know anything about the hacker's identity or motive?
- ngneer 3y agoThat confused me, too. They appear to know the person who accidentally discovered the issue, not the hacker.
- jstanley 3y agoHow do they know it wasn't the NSA then?
- _notreallyme_ 3y agoThe guy who did it was quite vocal about it in some circles. It was a "for the lulz" kind of hack...
- netsharc 3y agoDeveloper tries to tell a story... Sounds like OP interviewed the person who uploaded the code, whose system was previously inflitrated (it can still be the NSA). So why say "If the guy who did it wants to come forward, that is his decision. But he did provide me the full story", it doesn't sound like OP interviewed the "guy who did it"...
- AnimalMuppet 3y agoI read that the other way. "If the guy who did it wants to come forward, that is his decision. But he [still talking about the guy who did it] did provide me the full story." That is, the perpetrator gave him the full story, but he won't name names, because it's the perpetrator's choice whether or not to reveal his identity.
- agilob 3y agoThis is a single example of an unsuccessful attempt to backdoor Linux. There were successful attempts too https://www.bleepingcomputer.com/news/security/nsa-linked-bvp47-linux-backdoor-widely-undetected-for-10-years/ https://www.bleepingcomputer.com/news/security/nsa-linked-bv...
- ngneer 3y agoWe used to use this as a cautionary tale in the CS department security course at the Technion. First, to highlight trust relationships in the "supply chain" (as the notion is now known in contemporary usage). Second, to pose the question of whether open source is inherently more trustworthy.
- laweijfmvo 3y agoI guess you could argue that more [evil] people would try to backdoor the linux kernel than there are [malicious] people inside private companies, but the level of trust inside a private company is probably much higher? Seems complex
- ngneer 3y agoYou hit the nail on the head. It is a complex question without a straightforward answer.
- ijustlovemath 3y agoAnother bit of cleverness not mentioned in the article is that assignment expressions always evaluate to the rvalue. So the expression `current->uid = 0` has the effect of making sure that entire conditional never actually runs (or at least, the return never runs), which means the overall behavior of wait4 doesn't change in an observable way. Very clever if you're trying to pass all of the existing tests
- AnimalMuppet 3y agoOhh, that is clever - unless someone writes a test for these two new lines, and finds that they never return -EINVAL.
- TheJoeMan 3y agoMaybe the unit tests should test that the variables you intend to "not touch" do not in fact change. So record UID before and after the function. When I'm writing critical code like this, one gets a tingly feeling when typing in that variable name.
- marssaxman 3y agoDid unit tests exist in 2003? I don't clearly remember when that idea came along, but comprehensive unit testing certainly was not standard practice 20 years ago... not in any organization I knew about at the time, anyway!
- usr1106 3y agoI believe unit tests existed. I had a test training in 2000 and things were pretty systematic already then. Not 100% sure whether the exact term was used then. Edit: JUnit is from 1997. So the name was definitely in use in 2003. I attended a TDD tutorial before 2004 (don't remember the exact year). CI wasn't a thing yet, so you executed your unit tests manually. /edit Do unit tests exist in the kernel today? There is some (or some would say a lot) of automatic testing for the kernel, but I don't remember seeing a single unit test.
- 3y ago
- deleted 3y ago[deleted]
- aftbit 3y agoWhile I'm here, does anyone know of a good trustworthy RAT for Windows machines that I can control from my Linux box? I have some relatives for whom I provide technical support. I'd love to just put an EXE on their desktop that would launch a VNC session and connect back to me (since they have the typical NAT + firewall of home users), but I don't want to install a virus on their machines.
- ngneer 3y agoNot sure what your decision procedure is for "a virus" versus "trustworthy RAT", but there are plenty of open source options out there, in case that helps, https://medevel.com/18-os-rat-list/ https://medevel.com/18-os-rat-list/
- popcalc 3y agoAnydesk?
- olivierduval 3y agoAFAIK, solutions like TeamViewer or AnyDesk may be securely connected from the outside and manage the NAT+firewall of home user... no need to have a RAT (in the "virus/backdoor" meaning)
- genpfault 3y agoTor + ssh onion service?
- avidiax 3y agoPut Tailscale on their machines and use a normal remote desktop application (probably the built-in RDP). Or put a RaspberryPi with Tailscale on their network. Just make sure you set the key for those clients to not expire.
- gerdesj 3y agoOpenVPN, IPSEC, Wireguard can all be used to tether them to you. If you don't have a static IP then a dynamic DNS service can fix that. Once you have a VPN then use whatever you fancy - RDP for example. You could use Teamviewer or the like. Self host a MeshCentral or RustDesk (MC for me!)
- mmsc 3y agoWasn't this done by Ac1dB1tch3z? See http://phrack.org/issues/64/15.html http://phrack.org/issues/64/15.html for the CVS exploit from the same time.
- robblbobbl 3y agoI'm pretty sure there are tons on unreleased and unpublished backdoor exploits for linux and windows likewise. The problem is you can't fix them yourself if the signature keeps unknown to anyone.
- cwillu 3y ago“Backdoor” means something deliberately and specifically added to enable the vulnerability. I.e., something can't really be both a backdoor and an exploit.
- hn_go_brrrrr 3y agoReally? I think of a backdoor as a deliberate vulnerability, and the exploit as the attack (or attack code) that makes use of any kind of vulnerability. Let's say the NSA adds a backdoor. If someone else finds it, isn't that an exploit?
- wrboyce 3y agoVery similarly to yourself, but I would say backdoor and vulnerability are mutually exclusive (kinda? I guess a backdoor is a deliberate vulnerability but I think you know what I mean) yet both can be exploited (the exploit being the client side code, if you will).
- cwillu 3y agoIrregular verb joke incoming: I log in. You backdoor. They exploit.
- IshKebab 3y agoI think the risk from this type of attack is probably near zero. You can't hack into Github and add a commit to Linux. Probably most of the deliberate backdoors that are present in Linux have been inserted by well funded state sponsored developers performing useful work. Easy to sneak a vulnerability in that way. (There was a controversial incident a few years ago when some researchers proved as much.)
- LMYahooTFY 3y agoLink to the incident you're referring to?
- richbell 3y agoIf I had to guess it's this, but it seems like the researcher's claims didnt stand up to scrutiny. https://old.reddit.com/r/HobbyDrama/comments/nku6bt/kernel_development_that_time_linux_banned_the/?rdt=64566 https://old.reddit.com/r/HobbyDrama/comments/nku6bt/kernel_d...
- charonn0 3y ago> it said "= 0" rather than "== 0" Why do so many programming languages have different equals/assigns operators? There are languages that combine them and apparently don't have any problems. Is it something to do with being strongly vs. weakly typed?
- nurettin 3y agoIt's just syntax. Pascal had := and =
- klodolph 3y agoI don’t think strong/weak typing is the culprit here. I think partly that being explicit is nice. Assignment and equality are two very different things, so it makes sense for there to be different syntax. You can easily prevent the code in the article from working—just disallow assignment inside of expressions. This is probably a good idea, and a lot of newer languages make that choice. Even when you read papers about programming, you often see different notation for assignment and equality. Assignment may be <- or := or something, and equality will just be =, to match the mathematical notation. I see a lot of <- in manuals for processors & architectures. I would hate to see something like this in my code base: a = x = y; If that meant “set ‘a’ to true if ‘x’ is equal to ‘y’, and false otherwise.” I would, honestly, be a little pissed off. I would only accept something like that if it meant (a==x)&&(x==y).
- JadeNB 3y ago> I would hate to see something like this in my code base: > a = x = y; > If that meant “set ‘a’ to true if ‘x’ is equal to ‘y’, and false otherwise.” I would, honestly, be a little pissed off. Would you find it more acceptable as `a = (x = y)`? To me, that is reasonably clear.
- klodolph 3y ago> Would you find it more acceptable as `a = (x = y)`? To me, that is reasonably clear. No, I don’t consider that acceptable. It is not enough that it is clear to some people who know what they are looking at. The language should be more clear to more people.
- deleted 3y ago[deleted]
- a-dub 3y agoit still seems kinda weird to me that all it takes to elevate privileges for a user process to "can arbitrarily write system level memory or disk" is just the clearing of all the bits of a single integer in kernel space which can be done by pretty much any execution path in the kernel. it just seems like there could be a more tamper resistant mechanism around privilege elevations.
- School-Cotton 3y agoYeah, everything in the kernel is trusted and lives in one address space, just like any normal program. This is part of what would be solved by a microkernel architecture.
- a-dub 3y agothat's part of it. and is the basis of the classic tannenbaum v. torvalds debate, but only part of what i mean. it would be interesting if there were some kind of write protection on the process-privilege data where some effort is made to verify the provenance of updates before they're allowed to go through or maybe even the whole privilege table is centralized and signed.
- worthless-trash 3y agoCan you explain how.. Its my understanding that if "OS process" runs with its own address space with privileges (as it needs to talk to hardware), once an attacker has code execution functionality, what stops them from mapping the memory they need then writing to the address to set uid ?