I'm watching some folks reverse engineer the xz backdoor, sharing some *preliminary* analysis with permission.
The hooked RSA_public_decrypt verifies a signature on the server's host key by a fixed Ed448 key, and then passes a payload to system().
It's RCE, not auth bypass, and gated/unreplayable.
30.03.2024 17:13
π 687
π 275
π¬ 7
π 13
U.S. and French fake document generator
/spiceleads.cc
#scam #phishing @nytimes @washingtonpost.com @news-feed.bsky.social @infosec.skyfleet.blue
07.03.2024 08:56
π 1
π 0
π¬ 0
π 0
watch out, l is not i, info is not com, and
/twlitter.info is not
/twitter.com
#phishing
01.03.2024 09:45
π 4
π 1
π¬ 0
π 0
XSS #phishing
text.is/3KW7
26.02.2024 09:43
π 1
π 1
π¬ 0
π 0
watch out, fake @interpol.bsky.social #scam domain
/get-return.org
#scam #phishing
16.02.2024 13:07
π 0
π 0
π¬ 0
π 0
Public awareness is key to preventing
pig butchering #scam
www.youtube.com/watch?v=nDg2...
12.02.2024 08:38
π 1
π 1
π¬ 0
π 0
watch out, fake @interpol.bsky.social survey #scam domain
/internatinallhelp.org/form?p=413756227707060
#scam #phishing
07.02.2024 10:22
π 2
π 1
π¬ 0
π 0
hey whatβs up, Iβm illegalFawn and can help you in disrupting #phishing and #scam schemes, just tag me in your posts
07.02.2024 06:33
π 1
π 1
π¬ 0
π 0