{"id":13759,"date":"2024-04-18T15:05:29","date_gmt":"2024-04-18T09:05:29","guid":{"rendered":"https:\/\/dtasiagroup.com\/?p=13759"},"modified":"2024-06-19T13:24:54","modified_gmt":"2024-06-19T07:24:54","slug":"crisis-averted-a-recap-of-the-openssh-and-xz-liblzma-incident","status":"publish","type":"post","link":"https:\/\/dtasiagroup.com\/vi\/crisis-averted-a-recap-of-the-openssh-and-xz-liblzma-incident\/","title":{"rendered":"Crisis averted: A recap of the OpenSSH and XZ\/liblzma incident"},"content":{"rendered":"<div class=\"flex flex-grow flex-col max-w-full\">\n<div class=\"min-h-[20px] text-message flex flex-col items-start whitespace-pre-wrap break-words [.text-message+&amp;]:mt-5 juice:w-full juice:items-end overflow-x-auto gap-2\" dir=\"auto\" data-message-author-role=\"assistant\" data-message-id=\"13fa850e-c8d3-4f17-8155-a9ae315da087\">\n<div class=\"flex w-full flex-col gap-1 juice:empty:hidden juice:first:pt-[3px]\">\n<div class=\"markdown prose w-full break-words dark:prose-invert light\">\n<p>Recently, a new backdoor (CVE-2024-3094) was uncovered within the build system of the widely utilized xz-utils &#8216;liblzma&#8217; data compression library. This backdoor is purportedly aimed at the OpenSSH server but has the capability to affect any application that interacts with &#8216;systemd&#8217;, utilizes &#8216;OpenSSL&#8217;, and is accessible over the network. The complete extent and consequences of the backdoor remain unclear pending a thorough analysis of the injected malicious binary code.<\/p>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-13756\" src=\"https:\/\/dtasiagroup.com\/wp-content\/uploads\/2024\/04\/12978658182589666618.jpeg\" alt=\"\" width=\"1000\" height=\"522\" \/><\/p>\n<p><strong><span lang=\"EN-US\" xml:lang=\"EN-US\" data-contrast=\"auto\">Tectia SSH Client\/Server by SSH Communication Security is not affected by XZ\/liblzma\u00a0<\/span><\/strong><\/p>\n<div class=\"flex flex-grow flex-col max-w-full\">\n<div class=\"min-h-[20px] text-message flex flex-col items-start whitespace-pre-wrap break-words [.text-message+&amp;]:mt-5 juice:w-full juice:items-end overflow-x-auto gap-2\" dir=\"auto\" data-message-author-role=\"assistant\" data-message-id=\"15095cd4-7ee8-40db-8720-7b220260a41c\">\n<div class=\"flex w-full flex-col gap-1 juice:empty:hidden juice:first:pt-[3px]\">\n<div class=\"markdown prose w-full break-words dark:prose-invert light\">\n<p>At SSH Communications Security, we want to clarify that our remote server and application access product, Tectia SSH Client\/Server, remains unaffected by the liblzma vulnerability. As cybersecurity specialists, we prioritize risk mitigation and have deliberately minimized our reliance on external libraries. Any validated dependencies are included as part of our installation package.<\/p>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n<p>&nbsp;<\/p>\n<p><strong><span lang=\"EN-US\" xml:lang=\"EN-US\" data-contrast=\"auto\">How does the backdoor work?<\/span><\/strong><\/p>\n<div class=\"flex flex-grow flex-col max-w-full\">\n<div class=\"min-h-[20px] text-message flex flex-col items-start whitespace-pre-wrap break-words [.text-message+&amp;]:mt-5 juice:w-full juice:items-end overflow-x-auto gap-2\" dir=\"auto\" data-message-author-role=\"assistant\" data-message-id=\"23cfd00a-f387-46ac-beeb-328e062bf038\">\n<div class=\"flex w-full flex-col gap-1 juice:empty:hidden juice:first:pt-[3px]\">\n<div class=\"markdown prose w-full break-words dark:prose-invert light\">\n<p>The XZ\/liblzma backdoor remains dormant until activated, operating as follows:<\/p>\n<p>The Linux &#8216;systemd&#8217; super-service application library, &#8216;libsystemd&#8217;, relies on the compromised &#8216;liblzma&#8217; library. Many Linux server applications that utilize &#8216;libsystemd&#8217; allow &#8216;systemd&#8217; to monitor and manage execution, creating an indirect dependency on &#8216;liblzma&#8217;.<\/p>\n<p>The backdoored &#8216;liblzma&#8217; included an initialization routine that facilitated the injection of a backdoor into the server application when it is loaded into memory during startup.<\/p>\n<p>The malicious code was distributed disguised as test vectors within &#8216;liblzma&#8217; files and alterations to the &#8216;autoconf&#8217; script used in the build process. These modified sources were included in the build processes of numerous Linux distributions.<\/p>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n<p>&nbsp;<\/p>\n<p><strong>How was the liblzma backdoor injected into the library?<\/strong><\/p>\n<div class=\"flex flex-grow flex-col max-w-full\">\n<div class=\"min-h-[20px] text-message flex flex-col items-start whitespace-pre-wrap break-words [.text-message+&amp;]:mt-5 juice:w-full juice:items-end overflow-x-auto gap-2\" dir=\"auto\" data-message-author-role=\"assistant\" data-message-id=\"c613f729-b3f8-44fe-af32-526c78417ed0\">\n<div class=\"flex w-full flex-col gap-1 juice:empty:hidden juice:first:pt-[3px]\">\n<div class=\"markdown prose w-full break-words dark:prose-invert light\">\n<p>It&#8217;s a stark reality that one of the maintainers of the library inserted malicious code into it. CVE-2024-3094 represents a vulnerability found in the open-source library XZ Utils, originating from malicious code inserted by one of its maintainers.<\/p>\n<p>The adversary began contributing to the XZ project nearly two years ago. Gradually, they earned trust and credibility within the project, gaining expanded permissions for the repository. This progression led them to assume maintainer responsibilities and eventually acquire release-manager privileges.<\/p>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n<p>&nbsp;<\/p>\n<p><strong><span lang=\"EN-US\" xml:lang=\"EN-US\" data-contrast=\"auto\">How dangerous is the liblzma?<\/span>\u00a0<\/strong><\/p>\n<p>Ubuntu 24.04LTS was just a month away from being released with this backdoor, and other distributions were in a similar situation. Perhaps the most apt description is this: if left undiscovered, Linux servers would have been operating with a dormant threat waiting to be remotely activated. CVE-2024-3094 acts like a digital sleeper agent, awaiting a trigger to potentially unleash one of the most devastating cyberterrorism acts ever seen.<\/p>\n<p>&nbsp;<\/p>\n<p><strong><span lang=\"EN-US\" xml:lang=\"EN-US\" data-contrast=\"auto\">How was\u00a0liblzma\u00a0discovered?<\/span>\u00a0<\/strong><\/p>\n<p>Fortunately, this backdoor was detected early, ensuring the safety of most of the Linux user community. Much of the credit belongs to Andres Freund from Microsoft, who diligently investigated the slowdown in the PostgreSQL test lab and uncovered the liblzma backdoor.<\/p>\n<p>Thank you, Andres, for your dedicated efforts! Your work deserves global acknowledgment for averting what could have been a worldwide disaster.<\/p>\n<p>&nbsp;<\/p>\n<p><strong><span lang=\"EN-US\" xml:lang=\"EN-US\" data-contrast=\"auto\">Open source is free but comes with a cost<\/span><\/strong><\/p>\n<p>Regarding the risks associated with voluntarily maintained projects becoming integral to larger ecosystems: Users of open-source software (OSS) projects benefit from the original author&#8217;s work, often without adequate compensation or support. This imbalance can lead to a significant support burden on maintainers, eventually wearing them down.<\/p>\n<p>Bad actors volunteer to assist maintainers, possibly leveraging social pressure as a tactic. In return, they gain influence over the project, riding on the reputation of the original author and the established user base. The consequences are evident in hindsight.<\/p>\n<p>&nbsp;<\/p>\n<p>Source:\u00a0<a href=\"https:\/\/www.ssh.com\/blog\/a-recap-of-the-openssh-and-xz-liblzma-incident\">https:\/\/www.ssh.com\/blog\/a-recap-of-the-openssh-and-xz-liblzma-incident<\/a><\/p>\n<p>&nbsp;<\/p>\n<p><strong>About DT Asia<\/strong><\/p>\n<p>DT Asia began in 2007 with a clear mission to build the market entry for various pioneering IT security solutions from the US, Europe and Israel.<\/p>\n<p>Today, DT Asia is a regional, value-added distributor of cybersecurity solutions providing cutting-edge technologies to key government organisations and top private sector clients including global banks and Fortune 500 companies. We have offices and partners around the Asia Pacific to better understand the markets and deliver localised solutions.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Recently, a new backdoor (CVE-2024-3094) was uncovered within the build system of the widely utilized xz-utils &#8216;liblzma&#8217; data compression library. This backdoor is purportedly aimed at the OpenSSH server but has the capability to affect any application that interacts with &#8216;systemd&#8217;, utilizes &#8216;OpenSSL&#8217;, and is accessible over the network. The complete extent and consequences of the backdoor remain unclear pending a thorough analysis of the injected malicious binary code.<\/p>","protected":false},"author":11,"featured_media":13756,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[56],"tags":[],"class_list":["post-13759","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-articles"],"_links":{"self":[{"href":"https:\/\/dtasiagroup.com\/vi\/wp-json\/wp\/v2\/posts\/13759","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/dtasiagroup.com\/vi\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/dtasiagroup.com\/vi\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/dtasiagroup.com\/vi\/wp-json\/wp\/v2\/users\/11"}],"replies":[{"embeddable":true,"href":"https:\/\/dtasiagroup.com\/vi\/wp-json\/wp\/v2\/comments?post=13759"}],"version-history":[{"count":0,"href":"https:\/\/dtasiagroup.com\/vi\/wp-json\/wp\/v2\/posts\/13759\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/dtasiagroup.com\/vi\/wp-json\/wp\/v2\/media\/13756"}],"wp:attachment":[{"href":"https:\/\/dtasiagroup.com\/vi\/wp-json\/wp\/v2\/media?parent=13759"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/dtasiagroup.com\/vi\/wp-json\/wp\/v2\/categories?post=13759"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/dtasiagroup.com\/vi\/wp-json\/wp\/v2\/tags?post=13759"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}