This post discusses the xz attack shell script, which is part of a larger attack on the xz-utils software package. The attack involves injecting shell code during the build process and adding a nefarious object file to the software's test files. The object file contains a backdoor that enables the attacker to run code when a specific SSH certificate is presented.

24m read timeFrom research.swtch.com
Post cover image
Table of contents
IntroductionConfigureMake

Sort: