payload appears to have been hidden in test data then decrypted and injected during the build process.

  • @addie@feddit.uk
    link
    fedilink
    English
    31 year ago

    Okay - so it was cleverly hidden. Real question is what the binary blob does, so we can properly assess the damage…

    • underisk [none/use name]OP
      link
      fedilink
      English
      21 year ago

      Preliminary stuff I read yesterday suggests that it’s RCE triggered by a signal sent to SSHD. Safest bet is to nuke your system if you had the exploitable library running with an exposed sshd.