cstross,
@cstross@wandering.shop avatar

I got about halfway through skim-reading this before my eyes glazed over and my prefrontal lobe crashed to displaying a scrolling marquee saying THEY HAVE PLAYED US FOR ABSOLUTE FOOLS
https://hachyderm.io/@rsc/112200603337903320

jwildeboer,
@jwildeboer@social.wildeboer.net avatar

@cstross I have read the whole thing and understood most of it. It's a really interesting pile of obfuscation that is however not that relevant, once we knew what we are looking for. Reverse engineering the binary blob that got added this way is the more interesting part, IMHO :) And that work is being done and commented at several places as we speak. "Analysis of the payload" at https://gist.github.com/thesamesam/223949d5a074ebc3dce9ee78baad9e27

Steveg58,
@Steveg58@aus.social avatar

@cstross
As someone else pointed out this is an exploit of the GNU autoconf suite not an exploit of xz.

cstross,
@cstross@wandering.shop avatar

@Steveg58 Yes, this is simply how they smuggle the payload into the xz binary at build time without being noticed.

It's just that autoconf predates Posix, never mind LSB, and I can't help thinking a lot of what it does is thoroughly obsolescent cruft that provides camouflage for this kind of fuckery rather than doing anything anyone needs any more.

Di4na,
@Di4na@hachyderm.io avatar

@cstross tbf this is quite expected even of legitimate use of autoconf in any reasonably sized C project. Sadly

cstross,
@cstross@wandering.shop avatar

@Di4na It was careless meddling with a Beyond version of GNU autoconf that unleashed The Blight in "A Fire Upon The Deep", wasn't it.

Di4na,
@Di4na@hachyderm.io avatar

@cstross I mean. We are still paying the price of letting C escape out of containment

  • All
  • Subscribed
  • Moderated
  • Favorites
  • random
  • ngwrru68w68
  • rosin
  • GTA5RPClips
  • osvaldo12
  • love
  • Youngstown
  • slotface
  • khanakhh
  • everett
  • kavyap
  • mdbf
  • DreamBathrooms
  • thenastyranch
  • magazineikmin
  • megavids
  • InstantRegret
  • normalnudes
  • tacticalgear
  • cubers
  • ethstaker
  • modclub
  • cisconetworking
  • Durango
  • anitta
  • Leos
  • tester
  • provamag3
  • JUstTest
  • All magazines