Linux got wrecked by backdoor attack

preview_player
Показать описание
A popular compression library called XZ Utils was recently backdoored by a hacker which compromised Linux distros like Debian, OpenSUSE, Fedora, and Kali. Learn how the liblzma hack happened who is behind it.

#programming #linux #thecodereport

💬 Chat with Me on Discord

🔗 Resources

🔥 Get More Content - Upgrade to PRO

Use code YT25 for 25% off PRO access

🎨 My Editor Settings

- Atom One Dark
- vscode-icons
- Fira Code Font

🔖 Topics Covered

Overview of cve-2024-3094
Can Linux be hacked?
Who is behind XZ backdoor attack?
Home does XZ backdoor work?
Worst hacking incidents of 2024
Which Linux distros were affected by XZ attack?
Рекомендации по теме
Комментарии
Автор

Thank you for reporting this bug. The next version of the backdoor will no longer slow down your SSH server.

uplink-on-yt
Автор

A moment of silence for the NSA having lost one of their favorite tools 😔

jayshartzer
Автор

Attacker :- Plans for years to attack 🤡
Our guy :- CPU took too long (500 ms), I must check 🗿

Dira_
Автор

The guy helping to renovate the apartments, hiding cameras which are only caught because a slight increase in the electricity bill is such an amazingly good analogy, well done!

NeunEinser
Автор

Imagine planning this attack for 2 years just for someone to find it by accident because their CPU was 500 ms slower

cheezyskipper
Автор

Few percent of CPU usage increase and 500ms of additional delay when SSH into a machine ? Sus indeed amiright

Arckil
Автор

I manually came back to check the channel as I didn't notice any AI or tech industry updates via 'The Code Report' in my feed for the past 2 weeks

earthling_parth
Автор

Linux backdoor discovered.
Every tech youtuber: that's free content.

boltez
Автор

Guy who discovered pretty nasty backdoor because of CPU usage spike that lasts for couple of tenths of a second. Meanwhile, there are so many users that are unable to identify the friggin crypto miner on their system that eats 99% of their CPU/GPU all the time and think that it's just their machine "getting old".

pvc
Автор

I'm a life long nerd starting in security in middle school and an engineer now at 39. I live and breathe computers. My wife isnt in tech at all - but she just not 5 minutes ago told me about this hack and used the correct terms. I've never been more turned on.

rkonTheAutomator
Автор

The guy who found this and exposed it needs a medal. He prevented a disaster on the scale of any nuclear meltdown in terms of financial cost and damage to society.

iainballas
Автор

Well guys, it's been three weeks. They got him.

macknittle
Автор

This is why you're supposed to write your own operating system from the ground up

Codefan
Автор

Temple OS: 0 maintainers, 0 supply chain attacks...

vaisakhkm
Автор

The non-technical analogy is insanely accurate 3:29

kemzops
Автор

Help me step maintainer, my ssh login has a 500ms delay

RevenantCovenant
Автор

This is really concerning. It's clear how vital it's becoming to ensure the security of open source tools, particularly those that are widely used like XZ. It's scary to think what might have happened if this backdoor hadn't been discovered.

RILDIGITAL
Автор

excuse me sir, 3 weeks without a code report is getting painful. wish you the best sir

clooood
Автор

Working in cybersecurity a few years now, always overwhelmed to hear how monstrous are some security researchers are, detecting these random vulnerabilities.. impressive

ad
Автор

It is insane how that security expert took the time for such advanced diagnosis on an unstable distro from few subtle symptoms.
If that has been me, I would've simply nodded and said something in the lines of : "This is probably because it is an unstable version, they will probably fix it in the stable release" and moved on with my life.

TheYapster