4 ms·
> The FireWood backdoor, in a file named dbus, is the Linux OS continuation of the Project Wood malware... > The analyzed code suggests that the file usbdev.ko
by TacticalCoder 2y ago
> The FireWood backdoor, in a file named dbus, is the Linux OS continuation of the Project Wood malware...
> The analyzed code suggests that the file usbdev.ko is a kernel driver module working as a rootkit to hide processes.
Where is the backdoor coming from? If there's a backdoor, something is backdoored. An unknown exploit installing a rootkit and using a modified file, like usbdev.ko, is not a backdoor.
Which pakage / OS ships with the backdoor?
Or doesn't the author of TFA know the definition of a backdoor? Or is it me? I mean, to me the XZ utils exploit attempt was a backdoor (for example). But I see nothing here indicating the exploit they're talking about is a backdoor.
It reads like they classify anything opening ports and trying to evade detection as "backdoors".
Am I going nuts?
- remram 2y agoFits the usual definition, e.g. from Wikipedia: > A backdoor is a typically covert method of bypassing normal authentication or encryption
- aulin 2y agoAgree with OP, wikipedia is also wrong. A backdoor is something intentional. That definition fits any exploitable bug.
- wood_spirit 2y agoPerhaps we use the term back door in computer security because it comes from the general English expression to get someone or something in by the back door, which more generally is any exploit?
- remram 2y agoNeither Wikipedia nor GP said something about intentions. My understanding of GGP's complaint is that they'd refer to the package containing the security issue as "backdoor", rather than the malware itself, and I disagree. This driver thing is a backdoor, the package is backdoored, this fits usual definitions.
- NegativeK 2y agoI don't think you're going nuts, but I do think your definition of backdoor is a specific subset.
- tsimionescu 2y agoI believe any software that, once installed on a system, gives someone else remote access to control that system is "a backdoor". So the malware itself is "the backdoor", it's not a case of "package X has a backdoor that was exploited". Not all malware acts like a backdoor: some malware exfiltrates data, some seeks to destroy the system, some encrypts data to hold it hostage, some performs attacks on other systems using your CPU/IP/memory, etc. The malware they are describing here does act like a backdoor though, and doesn't seem to have other malicious behavior.
- Out_of_Characte 2y agoA backdoor is a literal door that the building was designed with. Whatever purpose it served, criminals could sometimes use it to gain covert access.
- wood_spirit 2y agofirewood is a back door, ie a program installed to provide access bypassing the systems normal authentication etc. The article says they don’t know how the attacker gets access to install this back door in the first place.
- shiroiushi 2y ago>The article says they don’t know how the attacker gets access to install this back door in the first place. It doesn't really matter, because it's orthogonal. Malware like this can be installed on a system through any exploit that provides sufficient access. So there's two parts to defending against it: 1) finding and fixing any vulnerability that allows the installation of malware like this, and 2) since #1 is a never-ending task, knowing about this malware so you can look specifically for it and delete it when you find it.
- internet_points 2y agoI agree, they're using the term backdoor in a much wider meaning than what's usually meant. E.g. the RSA created the Clipper Chip and intentionally inserted a backdoor to allow the government access, that's a backdoor. An attacker might use that later, but it was made by the original developer of the software with "good intentions". But TFA is using it to mean the situation where an attacker broke a window and climbed in from the outside and can now enter and leave through the hole they made.