Shadowing-Übung: Linux got wrecked by backdoor attack - Englisch Sprechen Lernen mit Video

Lektion wird erstellt...
1
Over the last few days, the open -source world has been in panic mode.
2
A highly sophisticated and carefully planned attack affecting the XZ compression tool was shipped to production,
3
and has compromised Linux distros like Debian, Kali, OpenSUSE, and others.
4
Thank God, TempleOS is unaffected though, and it's quite possibly one of the most well -executed supply chain attacks of all time,
5
and gives some random dude unfettered access to execute code on your machine via a secret backdoor.
6
This is not your everyday security vulnerability.
7
It's a threat -level midnight 10 .0 critical issue on the CVE Richter scale, even higher than famous bugs like Heartbleed, Log4Shell, and Shellshock.
8
In today's video, you'll learn exactly how the XZ backdoor works, and the incredible story of how it was discovered by accident.
9
It is April 1st, 2024, and you're watching the Code Report.
10
Unfortunately, this is not an April Fool's video.
11
If you happen to be using one of the Linux distros listed here, you'll want to upgrade immediately.
12
Luckily, it only affects a very narrow set of distros, most of which are unstable builds, but that's only because this backdoor was discovered by pure luck early on.
13
More on that in just a second, let's first take a deep dive into this backdoor.
14
XZ -Utils is a tool for compressing and decompressing streams based on the Lempel -Ziv Markov Chain Algorithm, or LZMA.
15
It contains a command line tool that's installed on most Linux distros by default, which you can use right now with the XZ command, but also contains an API library called lib -LZMA,
16
and many other pieces of software depend on this library to implement compression, One of which is SSHD, or Secure Shell Daemon, a tool that listens to SSH connections,
17
like when you connect your local machine to the terminal on a cloud server.
18
Now here's where the backdoor comes in, but keep in mind, researchers are still figuring out exactly how this thing works.
19
Malicious code was discovered in the tarballs of LibLZMA, which is the thing that most people actually install.
20
That malicious code is not present in the source code, though.
21
It uses a series of obfuscations to hide the malicious code, then at build time, it injects a pre -built object disguised as a test file that lives in the source code.
22
It modifies specific parts of the LZMA code, which ultimately allows the attacker to intercept and modify data that interacts with this library.
23
Researchers have also discovered that any payload sent to the backdoor must be signed by the attacker's private key.
24
In other words, the attacker is the only one who can send a payload to the backdoor, making it more difficult to test and monitor.
25
And the attacker went to great lengths to obfuscate the code, like it contains no ASCII characters and instead has a built -in state machine to recognize important strings.
26
Now, because the vast majority of servers that power the internet are Linux -based, this backdoor could have been a major disaster.
27
Luckily, though, a hero software engineer named Andres Freund was using the unstable branch of Debian to benchmark Postgres.
28
He noticed something weird that most people would overlook.
29
SSH logins were using up more CPU resources than normal.
30
Initially, he thought it was an issue in Debian directly, but after some investigation, discovered it was actually upstream in exeutils.
31
And that's really bad, because so many things depend on this tool.
32
In German, his last name translates to friend, which is fitting, because he single -handedly helped the world avoid a multi -billion dollar disaster. But whodunit?
33
Who's the bad guy here?
34
At this point, it's unclear.
35
The LibLZMA project is maintained by Lassie Collin.
36
However, the malicious tarballs are signed by Gia Tan, a contributor to the project.
37
This individual has been a trusted contributor for the last few years, but clearly, they've been playing the long game.
38
They spent years building up trust before trying the backdoor, and nobody even noticed when they made their move.
39
I say they because we don't know if this is an individual or a penetration attempt from a rogue state like Russia, North Korea, or the United States.
40
Here's a non -technical analogy.
41
Imagine there's a landlord, we'll call him Lassie Collin, who manages a popular apartment building.
42
It's a lot of work, but this young, enthusiastic guy has been super helpful over the last couple years, adding all sorts of upgrades and renovations.
43
Let's call him Gia Tan.
44
He does great work, but he's also been secretly installing cameras in the bathrooms, which only he can access from the internet with his password.
45
Now, he would have gotten away with it too if it weren't for a pesky tenant named Andres, who happened to notice that his electricity bill was just a little bit higher than usual.
46
He started looking behind the walls and found some unexpected wires that led right to the unauthorized cameras.
47
At this point, we don't know the true identity of the hacker, but whoever did this was looking to cast a very wide net, and because it's protected by a secret key, can only be exploited by one party.
48
XZ was a sitting duck because it's extremely popular, while also being very boring with a single maintainer.
49
Whoever's behind this is either an extremely intelligent psychopath, or more likely, a group of state -sponsored dimension -hopping lizard people hellbent on world domination.
50
And that's why the only distro you should use is TempleOS.
51
This has been The Code Report, thanks for watching, and I will see you in the next one.

Über diese Lektion

Was ist die Shadowing-Technik?

Shadowing ist eine wissenschaftlich fundierte Sprachlerntechnik, die ursprünglich für die professionelle Dolmetscherausbildung entwickelt und durch den Polyglotten Dr. Alexander Arguelles populär gemacht wurde. Die Methode ist einfach aber wirkungsvoll: Du hörst englisches Audio von Muttersprachlern und wiederholst es sofort laut — wie ein Schatten, der dem Sprecher mit nur 1–2 Sekunden Verzögerung folgt. Anders als passives Hören oder Grammatikübungen zwingt Shadowing dein Gehirn und deine Mundmuskulatur, gleichzeitig echte Sprachmuster zu verarbeiten und zu reproduzieren. Studien zeigen, dass es Aussprachegenauigkeit, Intonation, Rhythmus, verbundene Sprache, Hörverständnis und Sprechflüssigkeit signifikant verbessert — was es zu einer der effektivsten Methoden für die IELTS Speaking-Vorbereitung und reale englische Kommunikation macht.