|
|
Log in / Subscribe / Register

Obtaining a copy of the bad library

Obtaining a copy of the bad library

Posted Mar 30, 2024 23:08 UTC (Sat) by tarvin (guest, #4412)
Parent article: A backdoor in xz

Does someone know how to get hold of a liblzma.so.5 which has the backdoor code? I'd like to have some so-called antimalware products scan it and see if they detect anything bad with it. (My prejudice is that they will not flag it as bad, but maybe I'm wrong.)


to post comments

Obtaining a copy of the bad library

Posted Mar 31, 2024 6:41 UTC (Sun) by wsy (subscriber, #121706) [Link] (1 responses)

Obtaining a copy of the bad library

Posted Mar 31, 2024 11:26 UTC (Sun) by tarvin (guest, #4412) [Link]

Thanks. At the time of writing at VirusTotal, just three out of 76 so-called malware detection products flag an issue with the bad shared object file. Those three products are AliCloud, DrWeb, and Rising. None of the major antimalware tool vendors detect it.

This highlights the absurdity of some corporations' policies requiring that antivirus (which have many times itself suffered from security holes) be installed even on Linux systems.


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds