3 ms·
It would be really cool if in 20 years when we have quantum computers powerful enough we could see what this exploit does.
by BlueFalconHD 3y ago
It would be really cool if in 20 years when we have quantum computers powerful enough we could see what this exploit does.
- denysvitali 3y agoMy understanding is that we know somehow already what the exploit allows the attacker to do - we just can't reproduce it because we don't have their private key. Technically, we can modify the backdoor and embed our own public key - but there is no way to probe a random server on the internet and check if it's vulnerable (from a scanner perspective). In a certain way it's a good thing - only the creator of the backdoor can access your vulnerable system...
- tialaramex 3y agoIt's a NOBUS (Nobody But Us can use it) attack. The choice to use a private key means it's possible that even the person who submitted the tampered code doesn't have the private key, only some other entity controlling them does.
- _kbh_ 3y ago[dead]
- kortilla 3y agoWe do know what it does. If it decrypts it just passes to system().
- password4321 3y agoAFAIK still no luck with Gauss from 2012 https://securelist.com/gauss-abnormal-distribution/36620/ https://securelist.com/gauss-abnormal-distribution/36620/