lemmy.net.au
  • Communities
  • Create Post
  • Create Community
  • heart
    Support Lemmy
  • search
    Search
  • Login
  • Sign Up
monica_b1998@lemmy.world to Linux@programming.dev · 15 hours ago

China-Linked Hackers Backdoored Linux Login Software to Hide for Nearly a Decade

thehackernews.com

external-link
message-square
12
fedilink
24
external-link

China-Linked Hackers Backdoored Linux Login Software to Hide for Nearly a Decade

thehackernews.com

monica_b1998@lemmy.world to Linux@programming.dev · 15 hours ago
message-square
12
fedilink
Sygnia says Velvet Ant modified Linux PAM and OpenSSH components to steal credentials and maintain stealthy access since 2016.
  • Skullgrid@lemmy.world
    link
    fedilink
    arrow-up
    2
    ·
    edit-2
    14 hours ago

    what are we meant to do?

    • Maki@lemmy.blahaj.zone
      link
      fedilink
      arrow-up
      9
      ·
      11 hours ago

      Nothing. The group in question attacked a specific system. The title is misleading.

    • Ooops@feddit.org
      link
      fedilink
      arrow-up
      13
      ·
      edit-2
      14 hours ago

      Don’t let people steal your device to break into it and replace the login software with a compromised version…

    • WhoIzDisIz@lemmy.today
      link
      fedilink
      arrow-up
      4
      arrow-down
      2
      ·
      14 hours ago

      Go to something immutable.

      • PabloSexcrowbar@piefed.social
        link
        fedilink
        English
        arrow-up
        1
        ·
        7 hours ago

        I don’t know that the current crop of immutable distros would be able to prevent something like this. rpm-ostree, at least, lets you install out-of-tree rpm packages to the base system, you just have to reboot for them to take effect.

      • moonpiedumplings@programming.dev
        link
        fedilink
        arrow-up
        3
        ·
        12 hours ago

        Not really. Immutability can be overriden by root, who can then edit files.

        And in addition to that, /etc/, system config files, including pam files mentioned here, are not immuable even in immutable distros.

        • WhoIzDisIz@lemmy.today
          link
          fedilink
          arrow-up
          1
          ·
          8 hours ago

          TIL, TY.

Linux@programming.dev

linux@programming.dev

Subscribe from Remote Instance

Create a post
You are not logged in. However you can subscribe from another Fediverse account, for example Lemmy or Mastodon. To do this, paste the following into the search field of your instance: !linux@programming.dev

A community for everything relating to the GNU/Linux operating system (except the memes!)

Also, check out:

  • !linux_memes@programming.dev
  • !linuxphones@lemmy.ca
  • our Matrix group chat
  • !reactos@programming.dev

Original icon base courtesy of lewing@isc.tamu.edu and The GIMP

Visibility: Public
globe

This community can be federated to other instances and be posted/commented in by their users.

  • 451 users / day
  • 1.28K users / week
  • 3.57K users / month
  • 5.47K users / 6 months
  • 1 local subscriber
  • 14K subscribers
  • 563 Posts
  • 3.47K Comments
  • Modlog
  • mods:
  • Ategon@programming.dev
  • adr1an@programming.dev
  • dwraf_of_ignorance@programming.dev
  • BE: 0.19.9
  • Modlog
  • Instances
  • Docs
  • Code
  • join-lemmy.org