Live data from Hacker News

Xzbot: Notes, honeypot, and exploit demo for the xz backdoor

github.com

241–250 of 500 posts

Re: Xzbot: Notes, honeypot, and exploit demo for the xz backdoor

#241

One thing I notice about state-level espionage and backdoors. The USA seems to have an affinity for hardware interdiction as opposed to software backdoors. Hardware backdoors make sense since much of it passes through the USA. Other countries such as Israel are playing the long-con with very well engineered, multi-year software backdoors. A much harder game to play.

> Other countries such as Israel are playing the long-con with very well engineered, multi-year software backdoors What is this in reference to?

NSO Group

They are an Israel based company, that sell zero-click RCEs for phones and more. Such malicious software was involved in the murder of journalist Jamal Khashoggi.

Their exploits, developed in-house as well as presumably partially bought on the black market, are some of the most sophisticated exploits found in the wild, e.g. https://googleprojectzero.blogspot.com/2021/12/a-deep-dive-i...

> JBIG2 doesn't have scripting capabilities, but when combined with a vulnerability, it does have the ability to emulate circuits of arbitrary logic gates operating on arbitrary memory. So why not just use that to build your own computer architecture and script that!? That's exactly what this exploit does. Using over 70,000 segment commands defining logical bit operations, they define a small computer architecture with features such as registers and a full 64-bit adder and comparator which they use to search memory and perform arithmetic operations. It's not as fast as Javascript, but it's fundamentally computationally equivalent.

Re: Xzbot: Notes, honeypot, and exploit demo for the xz backdoor

#242

Is there anything actually illegal here? Like is it a plausible “business” model for talented and morally compromised developers to do this and then sell the private key to state actors without actually breaking in themselves or allowing anyone else to break in. Edit: MIT license provides a pretty broad disclaimer to say it isn’t fit for any purpose implied or otherwise.

I brought this up in an earlier thread and got heavily downvoted. https://news.ycombinator.com/item?id=39878227

Re: Xzbot: Notes, honeypot, and exploit demo for the xz backdoor

#243

Earlier quoted context omitted.

Don't have to do anything too complicated. Here's the knocker code in a short Bash script, produced by GPT4: ~ % gpt4 'write a very short bash script that takes the number stored in ~/.ssh/knock_seq, increments it by 1 and saves it to the file. It then takes the new number and concatenates it with the value stored in the file ~/.ssh/secret. It pipes the resulting string to sha1sum, spitting out binary. It then takes…

The knockee PoC should also be straightforward, can use socat + udp-listen + fork with a script that checks that input matches `sha1sum(secret||num)||num` and `num>previously_seen_num`, and if so, adds an iptables rule. This should prevent against replays. Throw in some rate limits somewhere maybe to not get DDoSed, especially if you let socat `fork`.

[deleted]

Re: Xzbot: Notes, honeypot, and exploit demo for the xz backdoor

#244
post #163

Earlier quoted context omitted.

It's worth also noting that the spycraft involved a coordinated harassment campaign of the original maintainer, with multiple writing styles, to accelerate a transition of maintainership to the attacker: https://www.mail-archive.com/xz-devel@tukaani.org/msg00566.h... https://www.mail-archive.com/xz-devel@tukaani.org/msg00568.h... https://www.mail-archive.com/xz-devel@tukaani.org/msg00569.h... While this doesn't prove…

At first I thought the guy who did this was a lone wolf but now I believe it was indeed state actor. They coordinated and harassed original maintainer into giving them access to the project, basically they hijacked the open source project. The poor guy(the original maintainer) was alone against state actor who was persistent with the goal of hijacking and then backdooring the open source project. It seems like they w…

Reading that link, it seems like the vulnerability is that a file name gets printed, so you can add terminal control characters in a file name and have it printed.

https://github.com/libarchive/libarchive/pull/1609#issuecomm...

Re: Xzbot: Notes, honeypot, and exploit demo for the xz backdoor

#245
post #16

It's pretty interesting that they didn't just introduce an RCE that anyone can exploit, it requires the attacker's private key. It's ironically a very security conscious vulnerability.

I suspect the original rationale is about preserving the longevity of the backdoor. If you blow a hole wide open that anyone can enter, it’s going to be found and shut down quickly. If this hadn’t had the performance impact that brought it quickly to the surface, it’s possible that this would have lived quietly for a long time exactly because it’s not widely exploitable.

Also people can come and immediately undo whatever you did if it's not authenticated.

Re: Xzbot: Notes, honeypot, and exploit demo for the xz backdoor

#246
post #240
post #221

Earlier quoted context omitted.

The libarchive diff didn't create any vulnerability. The fprintf calls were consistent with others in the same repository.

They still preferred to revert it as it looks very suspicious. https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1068047 https://github.com/libarchive/libarchive/pull/2101

If I read that correctly the problem is that it prints a filename that might include terminal control sequences that come from an attacker-controlled file name.

Comment in your second link:

https://github.com/libarchive/libarchive/pull/1609#issuecomm...

Re: Xzbot: Notes, honeypot, and exploit demo for the xz backdoor

#247

One thing I notice about state-level espionage and backdoors. The USA seems to have an affinity for hardware interdiction as opposed to software backdoors. Hardware backdoors make sense since much of it passes through the USA. Other countries such as Israel are playing the long-con with very well engineered, multi-year software backdoors. A much harder game to play.

I mean, they’re just the high profile ones. China makes and ships a lot of hardware, and the US makes and ships a lot of software.

Re: Xzbot: Notes, honeypot, and exploit demo for the xz backdoor

#248

Earlier quoted context omitted.

For real, it's almost like a state-sponsored exploit. It's crafted and executed incredibly well, the performance issue feels like pure luck it got found.

I don't think it was executed incredibly well. There were definitely very clever aspects but they made multiple mistakes - triggering Valgrind, the performance issue, using a `.` to break the Landlock test, not giving the author a proper background identity. I guess you could also include the fact that they made it a very obvious back door rather than an exploitable bug, but that has the advantage of only letting you…

Maybe it's the first successful attempt of a state which nobody would right now suspect as capable of carrying this out. Everyone is looking at the big guys but a new player has entered the game.

Re: Xzbot: Notes, honeypot, and exploit demo for the xz backdoor

#249

Earlier quoted context omitted.

Yes. This would surely be prosecutable under the CFAA. Honestly, if I were involved in this, I'd hope that it was, say, the FBI that caught me. I think that'd be the best chance of staying out of the Guantanamo Bay Hilton, laws be damned.

CIA didn't put anyone new into gitmo for years. The 30 remaining gitmo prisoners are all W Bush holdovers that all subsequent administrations forgot.

Conspiracy theorist: That's what they want you to believe.

And in fairness, the whole nature of their secrecy means there's no way to know for sure. It might be just a boogeyman kept around as a useful tool for scaring people into not breaking national security-level laws. I mean, it's not as though I want to go around hacking the planet, but the idea of ending up at a CIA "black site", assuming such things even exist, would be enough to keep me from trying it.

Re: Xzbot: Notes, honeypot, and exploit demo for the xz backdoor

#250

Earlier quoted context omitted.

For real, it's almost like a state-sponsored exploit. It's crafted and executed incredibly well, the performance issue feels like pure luck it got found.

I read someone speculating that the performance issue was intentional, so infected machines could be easily identified by an internet wide scan without arousing further suspicicion. If this is or becomes a widespread method, then anti-malware groups should perhaps conduct these scans themselves.

Very small differences in performance can be detected over the network as long as you have enough samples. Given that every port 22 is being hit by a gazillion attempts per day already, sample count shouldn’t be an issue.

So if distinguishing infected machines was their intention they definitely over-egged it.

Post reply on HN