The hooked RSA_public_decrypt verifies a signature on the server's host key by a fixed Ed448 key, and then passes a payload to system().
It's RCE, not auth bypass, and gated/unreplayable.
Looks like this got caught by chance. Wonder how long it would have taken otherwise.
www.openwall.com/lists/oss-se...
It has everything: malicious upstream, masterful obfuscation, detection due to performance degradation, inclusion in OpenSSH via distro patches for systemd support…
Now I’m curious what it does in RSA_public_decrypt
The hooked RSA_public_decrypt verifies a signature on the server's host key by a fixed Ed448 key, and then passes a payload to system().
It's RCE, not auth bypass, and gated/unreplayable.
Them: “So, you’re telling me I get to be other people’s hell?”
Me: “Yes, that’s the spirit.”
Them: “So, you’re telling me I get to be other people’s hell?”
Me: “Yes, that’s the spirit.”
[1] www.schneier.com/blog/archive...
(by writing zero code)
[1] www.schneier.com/blog/archive...
The inability to feel pain or regret is related to the self-destruction reflex.
The inability to feel pain or regret is related to the self-destruction reflex.
It’s a livestream of a guy harvesting baboon organs.
It’s a livestream of a guy harvesting baboon organs.