Workspace IndexDev Notes › SolarWinds — compromising the build server, not the code

#178PoC

SolarWinds — compromising the build server, not the code

The SolarWinds attack inserted malware during the build, so signed, trusted updates carried the backdoor to thousands of customers — proof that a valid signature says nothing about a clean build.

Not yet scoped.

Why

The PoC maps the build-pipeline attack to reproducible-builds and SLSA provenance as the defenses, framing the CI system as the highest-value target.

How it works

Not yet built.

← All Dev Notes · Workspace Index · Top ↑

솔라윈즈 — 코드가 아니라 빌드 서버를 침해하다

솔라윈즈 공격은 빌드 중에 악성코드를 삽입해, 서명되고 신뢰받는 업데이트가 백도어를 수천 고객에게 실어 날랐습니다 — 유효한 서명이 깨끗한 빌드에 대해 아무것도 말하지 않는다는 증거입니다.

아직 범위 미정.

이 PoC는 빌드 파이프라인 공격을 방어책인 재현 가능 빌드와 SLSA 프로비넌스에 매핑하여, CI 시스템을 최고 가치 표적으로 규정합니다.

동작 방식

아직 만들지 않음.

← 전체 개발 노트 · 워크스페이스 인덱스 · 맨 위 ↑