Close Menu
5gantennas.org5gantennas.org
  • Home
  • 5G
    • 5G Technology
  • 6G
  • AI
  • Data
    • Global 5G
  • Internet
  • WIFI
  • 5G Antennas
  • Legacy

Subscribe to Updates

Subscribe to our newsletter and never miss our latest news

Subscribe my Newsletter for New Posts & tips Let's stay updated!

What's Hot

4 Best Wi-Fi Mesh Networking Systems in 2024

September 6, 2024

India is on the brink of a new revolution in telecommunications and can lead the world with 6G: Jyotiraditya Scindia

August 29, 2024

Speaker Pelosi slams California AI bill headed to Governor Newsom as ‘ignorant’

August 29, 2024
Facebook X (Twitter) Instagram
Facebook X (Twitter) Instagram
5gantennas.org5gantennas.org
  • Home
  • 5G
    1. 5G Technology
    2. View All

    Deutsche Telekom to operate 12,500 5G antennas over 3.6 GHz band

    August 28, 2024

    URCA Releases Draft “Roadmap” for 5G Rollout in the Bahamas – Eye Witness News

    August 23, 2024

    Smart Launches Smart ZTE Blade A75 5G » YugaTech

    August 22, 2024

    5G Drone Integration Denmark – DRONELIFE

    August 21, 2024

    Hughes praises successful private 5G demo for U.S. Navy

    August 29, 2024

    GSA survey reveals 5G FWA has become “mainstream”

    August 29, 2024

    China Mobile expands 5G Advanced, Chunghwa Telecom enters Europe

    August 29, 2024

    Ateme and ORS Boost 5G Broadcast Capacity with “World’s First Trial of IP-Based Statmux over 5G Broadcast” | TV Tech

    August 29, 2024
  • 6G

    India is on the brink of a new revolution in telecommunications and can lead the world with 6G: Jyotiraditya Scindia

    August 29, 2024

    Vodafonewatch Weekly: Rural 4G, Industrial 5G, 6G Patents | Weekly Briefing

    August 29, 2024

    Southeast Asia steps up efforts to build 6G standards

    August 29, 2024

    Energy efficiency as an inherent attribute of 6G networks

    August 29, 2024

    Finnish working group launches push for 6G technology

    August 28, 2024
  • AI

    Speaker Pelosi slams California AI bill headed to Governor Newsom as ‘ignorant’

    August 29, 2024

    Why Honeywell is betting big on Gen AI

    August 29, 2024

    Ethically questionable or creative genius? How artists are engaging with AI in their work | Art and Design

    August 29, 2024

    “Elon Musk and Trump” arrested for burglary in disturbing AI video

    August 29, 2024

    Nvidia CFO says ‘enterprise AI wave’ has begun and Fortune 100 companies are leading the way

    August 29, 2024
  • Data
    1. Global 5G
    2. View All

    Global 5G Enterprise Market is expected to be valued at USD 34.4 Billion by 2032

    August 12, 2024

    Counterpoint predicts 5G will dominate the smartphone market in early 2024

    August 5, 2024

    Qualcomm’s new chipsets will power affordable 5G smartphones

    July 31, 2024

    Best Super Fast Download Companies — TradingView

    July 31, 2024

    Crypto Markets Rise on Strong US Economic Data

    August 29, 2024

    Microsoft approves construction of third section of Mount Pleasant data center campus

    August 29, 2024

    China has invested $6.1 billion in state-run data center projects over two years, with the “East Data, West Computing” initiative aimed at capitalizing on the country’s untapped land.

    August 29, 2024

    What is the size of the clinical data analysis solutions market?

    August 29, 2024
  • Internet

    NATO believes Russia poses a threat to Western internet and GPS services

    August 29, 2024

    Mpeppe grows fast, building traction among Internet computer owners

    August 29, 2024

    Internet Computer Whale Buys Mpeppe (MPEPE) at 340x ROI

    August 29, 2024

    Long-term internet computer investor adds PEPE rival to holdings

    August 29, 2024

    Biden-Harris Administration Approves Initial Internet for All Proposals in Mississippi and South Dakota

    August 29, 2024
  • WIFI

    4 Best Wi-Fi Mesh Networking Systems in 2024

    September 6, 2024

    Best WiFi deal: Save $200 on the Starlink Standard Kit AX

    August 29, 2024

    Sonos Roam 2 review | Good Housekeeping UK

    August 29, 2024

    Popular WiFi extender that eliminates dead zones in your home costs just $12

    August 29, 2024

    North American WiFi 6 Mesh Router Market Size, Share, Forecast, [2030] – அக்னி செய்திகள்

    August 29, 2024
  • 5G Antennas

    Nokia and Claro bring 5G to Argentina

    August 27, 2024

    Nokia expands FWA portfolio with new 5G devices – SatNews

    July 25, 2024

    Deutsche Telekom to operate 12,150 5G antennas over 3.6 GHz band

    July 24, 2024

    Vodafone and Ericsson develop a compact 5G antenna in Germany

    July 12, 2024

    Vodafone and Ericsson unveil new small antennas to power Germany’s 5G network

    July 11, 2024
  • Legacy
5gantennas.org5gantennas.org
Home»Internet»Major backdoor Internet security breach discovered by accident before implementation – MishTalk
Internet

Major backdoor Internet security breach discovered by accident before implementation – MishTalk

5gantennas.orgBy 5gantennas.orgMarch 31, 2024No Comments5 Mins Read
Facebook Twitter Pinterest LinkedIn Tumblr Email
Share
Facebook Twitter LinkedIn Pinterest WhatsApp Email


I’m fascinated by the story of how Microsoft engineers discovered a massive, well-hidden backdoor security breach that had been years in the making and nearly executed.

background

A widely used compression utility had a hidden software backdoor that allowed remote access to the entire system.

This was a years-long effort by a long-time trusted user named Jia Tan (@JiaT75). His account is now suspended everywhere.

HackerNews has an interesting excerpt.

Microsoft security researcher Andres Freund is said to have discovered and reported the issue on Friday.

The highly obfuscated malicious code was allegedly introduced by a user named JiaT75 through a series of four commits to the Tukaani project on GitHub.

long game

These open source projects are volunteer efforts. They pay nothing.

Lasse Collin (Larhzu), usually the head of the code, had been running the utility since 2009, but was suffering from burnout.

Jia Tan started contributing in the last 2-2.5 years, gained commit access about 1.5 years ago, and then gained release manager privileges.

Years of hacking plan reveals backdoor

Much of this story is very geeky and difficult to understand. Articles about the Unicorn Riot are readable.

Consider the backdoors revealed in years of hacking schemes

A fascinating but sinister software story was published on Friday. A widely used file compression software package called “xz utils” has a cleverly built-in system for backdooring shell login connections, allowing this dangerous package to reach countless internet-enabled devices. It is unclear whether there was an intrusion. It appears that Persona with this infusion has been able to play the long game and gain the trust of the official main developer, who has given them the authority to release new versions on their own.

andreas freund Reported this Friday morning on the industry security mailing listMany professionals spend their days poking under rocks and peering into the abyss of modern digital anxiety. “The upstream xz repository and xz tarball have been backdoored.” Freund wrote. It cleverly pokes holes in the SSH daemon (sshd), which is essential to modern computing at the most basic level.

Experts point out that the risk would have been extremely large if this had not been discovered. @thegrugq put it: “The ultimate goal is to be able to log into every Fedora, Debian, Ubuntu box on the Internet. If you’re not a state actor, you should be…”

Cryptographer Filippo Valsolda said: “This may be the most sophisticated supply chain attack we’ve ever reported publicly. It’s a nightmare scenario. , competent, and authorized.”

The issue was discovered after Freund noticed that a new version was slowing down tests on his PostgreSQL database and started debugging why this was happening. The backdoor caused a small but noticeable performance hit, which turns out to be a big boon for all types who are picky about benchmarks.

Ian Coldwater, a security expert in Minneapolis I got it., “Open source maintainer burnout is clearly a current security hazard. What are we doing about it?”

A June 2022 message from the original developer confessing to burnout shows how Jia Tan gained control of the software.

“I haven’t lost interest, but my ability to care is quite limited, mainly due to long-term mental health issues, but also other things. I did a little bit of work with Tan off-list, but maybe he’ll play a bigger role in the future.

It’s also good to keep in mind that this is a free hobby project.

Anyway, I can assure you that I am well aware of the issues where there is not much progress being made. The idea of ​​finding a new maintainer has been around for a long time, as the current situation is clearly bad and sad for the project.

The new XZ Utils stable branch will be released this year with thread decoder and more, followed by several alpha/beta releases. Perhaps immediately after the 5.4.0 release will be a convenient time to change the list of project administrators. Forking is obviously another possibility, but I have no control over that. […]”Lasse Collin, xz-devel mailing list, June 8, 2022

Some observers suspect that the persona that was attacking Colin via email may also have been a puppet trying to wrest control from him. In a detailed report, ARS Technica warned that malicious actors have made many changes to the binary test files over the years, so older versions may still have security issues.

Backdoor story now revealed

upstream backdoor

“Very annoying – the supposed backdoor author has been communicating with me for several weeks trying to add xz 5.6.x to Fedora 40 and 41 because it’s a “great new feature”.. We worked with him to fix a problem with valgrind (which we now know was caused by a backdoor he added). After the embargo was inadvertently lifted last night, we had to scramble to resolve the issue. ”

“He’s been working on the xz project for two years, adding all sorts of binary test files. Honestly, given this level of sophistication, I’m not sure if xz’s old I would doubt even the version.”

us security alert

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued an alert regarding CVE-2024-3094, a supply chain breach affecting the XZ Utils data compression library.

CISA and the open source community are responding to reports that XZ Utils versions 5.6.0 and 5.6.1 contain embedded malicious code. This activity has been assigned CVE-2024-3094. XZ Utils is data compression software and may be included in your Linux distribution. Malicious code may allow unauthorized access to an affected system.

Industry-wide calculations required

Masterdon user @glyph commented: “I really hope this will lead to industry-wide recognition of the practice of resting entire products on the shoulders of overworked workers who have a slow mental health crisis.” did. .

Here’s an interesting timeline of how this was almost implemented:

this is hero

Wow, just amazing.

It will probably take a few days for this code to be implemented.





Source link

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleSpaceX’s Starlink aims to transform mobile internet access
Next Article Internet crimes against children in Wyoming skyrocket, up 60% so far this year
5gantennas.org
  • Website

Related Posts

NATO believes Russia poses a threat to Western internet and GPS services

August 29, 2024

Mpeppe grows fast, building traction among Internet computer owners

August 29, 2024

Internet Computer Whale Buys Mpeppe (MPEPE) at 340x ROI

August 29, 2024
Leave A Reply Cancel Reply

You must be logged in to post a comment.

Latest Posts

4 Best Wi-Fi Mesh Networking Systems in 2024

September 6, 2024

India is on the brink of a new revolution in telecommunications and can lead the world with 6G: Jyotiraditya Scindia

August 29, 2024

Speaker Pelosi slams California AI bill headed to Governor Newsom as ‘ignorant’

August 29, 2024

Crypto Markets Rise on Strong US Economic Data

August 29, 2024
Don't Miss

Business News | Communications Minister Scindia promotes 6G leadership and nationwide broadband in meeting with telecom operators

By 5gantennas.orgAugust 24, 2024

New Delhi [India]August 24 (ANI): Union Telecom Minister Jyotiraditya Scindia along with Minister of State…

SingTel and SK Telecom prepare for the 6G future

July 8, 2024

Apple focuses on 6G for future iPhones

December 11, 2023

Subscribe to Updates

Subscribe to our newsletter and never miss our latest news

Subscribe my Newsletter for New Posts & tips Let's stay updated!

About Us
About Us

Welcome to 5GAntennas.org, your reliable source for comprehensive information on 5G technology, artificial intelligence (AI), and data-related advancements. We are passionate about staying at the forefront of these cutting-edge fields and bringing you the latest insights, trends, and developments.

Facebook X (Twitter) Pinterest YouTube WhatsApp
Our Picks

4 Best Wi-Fi Mesh Networking Systems in 2024

September 6, 2024

India is on the brink of a new revolution in telecommunications and can lead the world with 6G: Jyotiraditya Scindia

August 29, 2024

Speaker Pelosi slams California AI bill headed to Governor Newsom as ‘ignorant’

August 29, 2024
Most Popular

Will 5G make 2024 the most connected year in the industry?

December 1, 2023

The current state of 5G in the US and how it can improve

September 28, 2023

How 5G technology will transform gaming on the go

January 31, 2024
© 2026 5gantennas. Designed by 5gantennas.
  • Home
  • About us
  • Contact us
  • DMCA
  • Privacy Policy
  • About Creator

Type above and press Enter to search. Press Esc to cancel.