Workspace IndexDev Notes › XZ Utils backdoor — a supply-chain attack that almost shipped

#177PoC

XZ Utils backdoor — a supply-chain attack that almost shipped

The 2024 XZ backdoor was a multi-year social-engineering campaign that planted an SSH bypass in a core Linux compression library, caught by luck days before wide release.

Not yet scoped.

Why

The PoC studies the maintainer-trust attack rather than the payload — how a patient contributor earned commit rights — because the human supply chain is the vulnerability here.

How it works

Not yet built.

← All Dev Notes · Workspace Index · Top ↑

XZ Utils 백도어 — 거의 배포될 뻔한 공급망 공격

2024년 XZ 백도어는 핵심 리눅스 압축 라이브러리에 SSH 우회를 심은 다년간의 사회공학 캠페인이었고, 광범위 배포 며칠 전 운으로 발각됐습니다.

아직 범위 미정.

이 PoC는 페이로드가 아니라 관리자 신뢰 공격 — 인내심 있는 기여자가 커밋 권한을 얻은 과정 — 을 연구합니다. 여기서 취약점은 인간 공급망이기 때문입니다.

동작 방식

아직 만들지 않음.

← 전체 개발 노트 · 워크스페이스 인덱스 · 맨 위 ↑