[-] emidio 37 points 10 months ago

For the person receiving it it's correct

[-] emidio 12 points 11 months ago

That's being poly

[-] emidio 10 points 11 months ago

Yes, indeed the backdoor code checks, in the event of ssh authentication with a certificate, that it was signed with a specific ssh private key (their own CA), the corresponding public key being hardcoded in the backdoor code.

But this project xzbot demonstrates how to patch the corrupted liblzma to replace the key

[-] emidio 7 points 11 months ago* (last edited 11 months ago)

Oh thank you so much for these instructions I'll go through them on my computer.

I indeed wanted to know if the versions were still downloadable anywhere but if you can still install the correct liblzma version on any version of the distribution that works. I tried on a Debian VM on mac but with too little knowledge and it never run the correct liblzma

xzbot from Anthony Weems enables to patch the corrupted liblzma to change the private key used to compare it to the signed ssh certificate, so adding this to your instructions might enable me to demonstrate sshing into the VM :)

41
submitted 11 months ago by emidio to c/linux@lemmy.ml

Hi ! I want to demo the backdoor usage and would like to install a unstable/test version of a distribution (possibly Debian or Fedora) that had the backdoor (v5.6.0 or 5.6.1 of xz/liblzma and patched openssh for systemd notification)

How could I do that?

I will be using xzbot from amlweems to further patch liblzma but I want a distro that has openssh run by systemd that links to the correct liblzma version

Thank you!

[-] emidio 43 points 2 years ago

Wow look, new markdown syntax juste dropped decades ago

[-] emidio 38 points 2 years ago
[-] emidio 26 points 2 years ago

Sorry, shall I make another meme for you to spit it out?

1053
submitted 2 years ago by emidio to c/memes@lemmy.ml

(OC)

Alt text:

Timeline reading "All ties" from the far left until "Invention of scissors, -3000". Then it's reading "Rock advantage" until a second marker called "Invention of paper, -179". The final description from there to the far right reads "Balanced".

[-] emidio 14 points 2 years ago

FOSS doesn't mean your product/service/app is free to use

[-] emidio 12 points 2 years ago

China is already communist

[-] emidio 8 points 2 years ago

Nobody ate meat before very recently. And cheese was not your typical daily treat. Remembers it takes a long time to produce

[-] emidio 25 points 2 years ago

I agree with you but not on the last point. There is a difference since they are real people, adults, and that they consent on being sexually attractive and arouse. I am not attracted to young looking bodies but that's a notable difference to me. Also I don't know how I feel about a community (in a broader way than a lemmy comm) focusing and fetichising on young looking adults (I do know that it disturbs me but I want to talk about society wise), but I understand that some people are attracted to young looking bodies and/or juvenile ones, and I feel like adults that consent to answer their desires is better than CASM

[-] emidio 226 points 2 years ago

I know it's a shipost and this meme is at least 15 years old. But meat, cheese, and white bread (especially the ones in the US with added sugar) were never healthy

view more: next ›

emidio

joined 2 years ago