A supply chain attack on PyTorch
johnstawinski.com
A supply chain attack on PyTorch
1–10 of 109 posts
Re: A supply chain attack on PyTorch
#2> We used our C2 repository to execute the pwd && ls && /home && ip a command on the runner labeled “jenkins-worker-rocm-amd-34”, confirming stable C2 and remote code execution. We also ran sudo -l to confirm we had root access.
While it's not clear was it curated list of commands or just ALL, I assume the latter and that makes me feel no system administrator was involved into that pipelines setup - those guys are quite allergic to giving sudo/root access at all
Re: A supply chain attack on PyTorch
#3Re: A supply chain attack on PyTorch
#4i wonder about the over-dependence on third party packages and modules
imagine the author of 'is-odd' injects a trojan there
what are you gonna do?
C has this solved but 'vendoring' is not as fast as this approach
Re: A supply chain attack on PyTorch
#5Lockheed being listed makes me wonder if the FBI/CIA really will (further) step up on cybercrime, because you now have potential national security implications in a core supplier to multiple military branches.
Re: A supply chain attack on PyTorch
#6Is 5k an appropriate amount for such a finding? Sounds incredibly cheap for such a large organization. How much would something like this be worth on the black market?
Re: A supply chain attack on PyTorch
#7Is 5k an appropriate amount for such a finding? Sounds incredibly cheap for such a large organization. How much would something like this be worth on the black market?
you have to consider that in the black market the rates would absorb the illegality of the action. while 5k is 'clean'
Re: A supply chain attack on PyTorch
#8Re: A supply chain attack on PyTorch
#9Is 5k an appropriate amount for such a finding? Sounds incredibly cheap for such a large organization. How much would something like this be worth on the black market?
I think supply chain attacks are not being taken very seriously. Think that people working, for example, in Python or JavaScript use pip or npm daily no matter if they work for a nuclear agency or your uncle's bar.
Re: A supply chain attack on PyTorch
#10Hm, from the reading, it seem he was pretty careful to not do any harm, but still, is this type of practical research actually legal?
However, not all organizations are happy to be contacted about security issues. Sometimes doing the right thing can still result in (threats of) legal repercussions.
https://arstechnica.com/tech-policy/2021/10/missouri-gov-cal...