ISC StormCast for Monday, April 1st, 2024
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 1 April 2024
⏱️ 8 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello and welcome to the Monday, April 1st, 2024 edition of the Sandsenet Storm Center's Stormcast. |
| 0:08.3 | My name is Johannes Ulrich and I'm recording from Jacksonville, Florida. |
| 0:14.1 | Well, I'll do something a little bit different today and that's covering only one individual topic on Friday, Andrus Freund did publish a mailing list post to the |
| 0:26.5 | open source security mailing list, and in this post, Andrews Freund did explain his work in discovering |
| 0:35.8 | a backdoor in the popular XC Util package. |
| 0:41.1 | XC Utils includes a popular compression library and utilities to use this library. |
| 0:48.7 | The backdoor itself was actually in the compression library, and then, of course, potentially by running the tools, |
| 0:56.9 | you could start the back door, but that's not actually how it works. This backdoor specifically |
| 1:04.1 | targets System D. System D is used to launch various demons, and the way the back door works is that essentially |
| 1:13.4 | it waits for connections to the SSH demon. |
| 1:18.3 | And no, it's not one of those simple, hey, you connect with the right key and you are logged |
| 1:23.0 | in. |
| 1:23.7 | It's a bit more complex in that it looks for the right key, but then actually executes |
| 1:29.9 | code that is being sent by the user, so the user actually never logs in. |
| 1:36.7 | So again, version 560 and 561 are affected. |
| 1:41.9 | Luckily, these versions were released relatively recently. So for the few versions |
| 1:47.6 | that are affected, like for example, Arch Linux and Kali Linux, they're only affected if you |
| 1:54.3 | update it within approximately the last week. You're also not affected if you are running on a processor other than x86-64, |
| 2:03.6 | so all your Raspberry Pi users are not affected. And in Mac OS, if you are using HomePro |
| 2:12.4 | to install packages, you may have received the backdoor version last week, but this particular backdoor |
| 2:21.2 | was actually not included based on how this particular version was created. And with that, |
| 2:28.0 | let's talk a little bit about the history and sort of what we currently know about what exactly |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

