120
submitted 1 year ago by L4s@lemmy.world to c/technology@lemmy.world

Chinese hackers have unleashed a never-before-seen Linux backdoor::SprySOCKS borrows from open source Windows malware and adds new tricks.

you are viewing a single comment's thread
view the rest of the comments
[-] MonkderZweite@feddit.ch 14 points 1 year ago* (last edited 1 year ago)

Ok, but what does it attack? Systemd, udev, fuse, …?

[-] sirico@feddit.uk 13 points 1 year ago
[-] Zeth0s@lemmy.world 6 points 1 year ago

So it's not general to every linux distro, is it?

[-] sirico@feddit.uk 10 points 1 year ago

I could be wrong but this is a quick summary as I would look at it. As the Sysop for a small company running linux

Fortinet FortiOS, FortiProxy, and FortiSwitchManager:
    Type: Authentication bypass vulnerability
    Impact: If you're using any of these Fortinet products, an attacker could bypass authentication mechanisms and potentially access or control the system.
    Affect on Linux users: Only those Linux users who have these Fortinet products in their environments would be affected.

CVE-2022-39952:
    Product: Fortinet FortiNAC
    Type: Unauthenticated remote code execution (RCE)
    Impact: Attackers can remotely execute code without authentication.
    Affect on Linux users: Relevant for Linux users/administrators who use Fortinet FortiNAC in their network.

CVE-2021-22205:
    Product: GitLab CE/EE
    Type: Unauthenticated RCE
    Impact: An attacker could remotely execute code without authentication on GitLab instances.
    Affect on Linux users: This would affect Linux users who host or interact with GitLab CE/EE instances.

CVE-2019-18935:
    Product: Progress Telerik UI for ASP.NET AJAX
    Type: Unauthenticated RCE
    Impact: Allows remote code execution on affected servers using this UI component.
    Affect on Linux users: Most Linux users would not be impacted unless they host ASP.NET applications using this specific UI component.

CVE-2019-9670 / CVE-2019-9621:
    Product: Zimbra Collaboration Suite
    Type: Bundle of two vulnerabilities for unauthenticated RCE
    Impact: Attackers can remotely execute code without authentication on systems using Zimbra.
    Affect on Linux users: Linux users who use or host the Zimbra Collaboration Suite would be affected.

ProxyShell (CVE-2021-34473, CVE-2021-34523v, CVE-2021-31207):
    Product: Microsoft Exchange
    Type: Set of three chained vulnerabilities for unauthenticated RCE
    Impact: Attackers can exploit these vulnerabilities in sequence to remotely execute code on Exchange servers.
    Affect on Linux users: This primarily impacts organizations that run Microsoft Exchange servers. Directly, Linux users wouldn't be affected unless they interact with or administer these servers.
[-] Zeth0s@lemmy.world 7 points 1 year ago

Thanks, my understanding as well. A clickbait title...

this post was submitted on 19 Sep 2023
120 points (93.5% liked)

Technology

59623 readers
1375 users here now

This is a most excellent place for technology news and articles.


Our Rules


  1. Follow the lemmy.world rules.
  2. Only tech related content.
  3. Be excellent to each another!
  4. Mod approved content bots can post up to 10 articles per day.
  5. Threads asking for personal tech support may be deleted.
  6. Politics threads may be removed.
  7. No memes allowed as posts, OK to post as comments.
  8. Only approved bots from the list below, to ask if your bot can be added please contact us.
  9. Check for duplicates before posting, duplicates may be removed

Approved Bots


founded 1 year ago
MODERATORS