Jia Tan "cleaned up" in all their ZSTD branches some hours ago, probably hiding something https://github.com/JiaT75/zstd/branches/all
Backdoor in upstream xz/liblzma leading to SSH server compromise
951–960 of 1001 posts
Re: Backdoor in upstream xz/liblzma leading to SSH server compromise
#952Unfortunately, this is how good bad actors work: with a very long-term point of view. There is no “harmless” project any more.
Re: Backdoor in upstream xz/liblzma leading to SSH server compromise
#953Earlier quoted context omitted.
I think this has been in the making for almost a year. The whole ifunc infrastructure was added in June 2023 by Hans Jansen and Jia Tan. The initial patch is "authored by" Lasse Collin in the git metadata, but the code actually came from Hans Jansen: https://github.com/tukaani-project/xz/commit/ee44863ae88e377... > Thanks to Hans Jansen for the original patch. https://github.com/tukaani-project/xz/pull/53 There were…
Does anybody know anything about Jia Tan? Is it likely just a made up persona? Or is this a well-known person.
Re: Backdoor in upstream xz/liblzma leading to SSH server compromise
#954Re: Backdoor in upstream xz/liblzma leading to SSH server compromise
#955For someone who does not understand the packages used, could you please summarize in layman non technical terms. Thanks I did read the main post.
Re: Backdoor in upstream xz/liblzma leading to SSH server compromise
#956Re: Backdoor in upstream xz/liblzma leading to SSH server compromise
#957For someone who does not understand the packages used, could you please summarize in layman non technical terms. Thanks I did read the main post.
This link helped a little. https://gist.github.com/thesamesam/223949d5a074ebc3dce9ee78b...
https://gist.github.com/thesamesam/223949d5a074ebc3dce9ee78b...
Re: Backdoor in upstream xz/liblzma leading to SSH server compromise
#958Yikes! Do you have any info on the individual's background or possible motivations?
There is zero web presence for this person and associated email address. Looks more likely a fake identity than compromised account.
But wait, 2021 is his active year, but he missed almost all Aug. Is he on holiday? Who can have such a long holiday? What i can think is a solider who has a long vacation (探亲假). So let's guess he is a solider then it's sense that he worked on Spring Holiday because they need on duty. Let's double check again, if he is a solider, then they will have a holiday on every Aug. 1 because it's liberation army day. I check and no commits on all 4 years Aug. 1.
Re: Backdoor in upstream xz/liblzma leading to SSH server compromise
#959It was probably a tactic to give a reason to upgrade. It's not always a fault for those who did or tried to do.
Re: Backdoor in upstream xz/liblzma leading to SSH server compromise
#960Yikes! Do you have any info on the individual's background or possible motivations?