3 ms·
Ah. I thought this might be a discussion of “so, was this used?” The potential targets were many, but it almost seems like a supply-chain attack with more speci
by b33j0r 3y ago
Ah. I thought this might be a discussion of “so, was this used?” The potential targets were many, but it almost seems like a supply-chain attack with more specific targets.
It’s quite possible it wasn’t meant to stick around longer than a specific operation/breach. For example, it doesn’t run on ARM. It was “always on.” The committer added binary files to the repo (this one… I get the social engineering here… but I can’t see allowing it like this, even for testing a compression lib).
Also, it’s an expensive exploit to deploy. You can’t use this vector anymore.
Now. If someone expected a universal backdoor that would last years, like for law enforcement or intelligence, those things probably wouldn’t work.
On the other hand, if you needed to open a specific attack surface temporarily, it’s pretty brilliant.
Counter-argument is that you’d have to sort of know your target’s upgrade cadence, that the target entry is on x86 (likely, I guess), and that you wouldn’t get caught probing the ssh auth until it works.
- tmm84 3y agoI've felt that way since the news on this first came out. The placement, the library, etc. wouldn't last very long but if you knew your targets and just needed access it would work long enough for the purpose. Whether this was for posterity, the lolz, POC or whatever it did work. The bigger idea is whether or not the perp has bigger more elaborate exploits in the works or already deployed.