emidio

joined 1 year ago
[–] [email protected] 12 points 5 months ago (13 children)

That's being poly

[–] [email protected] 10 points 6 months ago

Yes, indeed the backdoor code checks, in the event of ssh authentication with a certificate, that it was signed with a specific ssh private key (their own CA), the corresponding public key being hardcoded in the backdoor code.

But this project xzbot demonstrates how to patch the corrupted liblzma to replace the key

[–] [email protected] 6 points 6 months ago* (last edited 6 months ago) (1 children)

Oh thank you so much for these instructions I'll go through them on my computer.

I indeed wanted to know if the versions were still downloadable anywhere but if you can still install the correct liblzma version on any version of the distribution that works. I tried on a Debian VM on mac but with too little knowledge and it never run the correct liblzma

xzbot from Anthony Weems enables to patch the corrupted liblzma to change the private key used to compare it to the signed ssh certificate, so adding this to your instructions might enable me to demonstrate sshing into the VM :)

[–] [email protected] -1 points 1 year ago (6 children)

China is already communist

[–] [email protected] 0 points 1 year ago (1 children)

Taking things for granted on an open-source software without willing to do anything

[–] [email protected] 1 points 1 year ago

I know it's a shipost and this meme is at least 15 years old. But meat, cheese, and white bread (especially the ones in the US with added sugar) were never healthy

view more: ‹ prev next ›