쉐도잉 연습: Linux got wrecked by backdoor attack - 영상으로 영어 말하기 배우기
레슨 만드는 중...
1
Over the last few days, the open -source world has been in panic mode.
2
A highly sophisticated and carefully planned attack affecting the XZ compression tool was shipped to production,
3
and has compromised Linux distros like Debian, Kali, OpenSUSE, and others.
4
Thank God, TempleOS is unaffected though, and it's quite possibly one of the most well -executed supply chain attacks of all time,
5
and gives some random dude unfettered access to execute code on your machine via a secret backdoor.
6
This is not your everyday security vulnerability.
7
It's a threat -level midnight 10 .0 critical issue on the CVE Richter scale, even higher than famous bugs like Heartbleed, Log4Shell, and Shellshock.
8
In today's video, you'll learn exactly how the XZ backdoor works, and the incredible story of how it was discovered by accident.
9
It is April 1st, 2024, and you're watching the Code Report.
10
Unfortunately, this is not an April Fool's video.
11
If you happen to be using one of the Linux distros listed here, you'll want to upgrade immediately.
12
Luckily, it only affects a very narrow set of distros, most of which are unstable builds, but that's only because this backdoor was discovered by pure luck early on.
13
More on that in just a second, let's first take a deep dive into this backdoor.
14
XZ -Utils is a tool for compressing and decompressing streams based on the Lempel -Ziv Markov Chain Algorithm, or LZMA.
15
It contains a command line tool that's installed on most Linux distros by default, which you can use right now with the XZ command, but also contains an API library called lib -LZMA,
16
and many other pieces of software depend on this library to implement compression, One of which is SSHD, or Secure Shell Daemon, a tool that listens to SSH connections,
17
like when you connect your local machine to the terminal on a cloud server.
18
Now here's where the backdoor comes in, but keep in mind, researchers are still figuring out exactly how this thing works.
19
Malicious code was discovered in the tarballs of LibLZMA, which is the thing that most people actually install.
20
That malicious code is not present in the source code, though.
21
It uses a series of obfuscations to hide the malicious code, then at build time, it injects a pre -built object disguised as a test file that lives in the source code.
22
It modifies specific parts of the LZMA code, which ultimately allows the attacker to intercept and modify data that interacts with this library.
23
Researchers have also discovered that any payload sent to the backdoor must be signed by the attacker's private key.
24
In other words, the attacker is the only one who can send a payload to the backdoor, making it more difficult to test and monitor.
25
And the attacker went to great lengths to obfuscate the code, like it contains no ASCII characters and instead has a built -in state machine to recognize important strings.
26
Now, because the vast majority of servers that power the internet are Linux -based, this backdoor could have been a major disaster.
27
Luckily, though, a hero software engineer named Andres Freund was using the unstable branch of Debian to benchmark Postgres.
28
He noticed something weird that most people would overlook.
29
SSH logins were using up more CPU resources than normal.
30
Initially, he thought it was an issue in Debian directly, but after some investigation, discovered it was actually upstream in exeutils.
31
And that's really bad, because so many things depend on this tool.
32
In German, his last name translates to friend, which is fitting, because he single -handedly helped the world avoid a multi -billion dollar disaster. But whodunit?
33
Who's the bad guy here?
34
At this point, it's unclear.
35
The LibLZMA project is maintained by Lassie Collin.
36
However, the malicious tarballs are signed by Gia Tan, a contributor to the project.
37
This individual has been a trusted contributor for the last few years, but clearly, they've been playing the long game.
38
They spent years building up trust before trying the backdoor, and nobody even noticed when they made their move.
39
I say they because we don't know if this is an individual or a penetration attempt from a rogue state like Russia, North Korea, or the United States.
40
Here's a non -technical analogy.
41
Imagine there's a landlord, we'll call him Lassie Collin, who manages a popular apartment building.
42
It's a lot of work, but this young, enthusiastic guy has been super helpful over the last couple years, adding all sorts of upgrades and renovations.
43
Let's call him Gia Tan.
44
He does great work, but he's also been secretly installing cameras in the bathrooms, which only he can access from the internet with his password.
45
Now, he would have gotten away with it too if it weren't for a pesky tenant named Andres, who happened to notice that his electricity bill was just a little bit higher than usual.
46
He started looking behind the walls and found some unexpected wires that led right to the unauthorized cameras.
47
At this point, we don't know the true identity of the hacker, but whoever did this was looking to cast a very wide net, and because it's protected by a secret key, can only be exploited by one party.
48
XZ was a sitting duck because it's extremely popular, while also being very boring with a single maintainer.
49
Whoever's behind this is either an extremely intelligent psychopath, or more likely, a group of state -sponsored dimension -hopping lizard people hellbent on world domination.
50
And that's why the only distro you should use is TempleOS.
51
This has been The Code Report, thanks for watching, and I will see you in the next one.
이 레슨에 대해
"Linux got wrecked by backdoor attack"으로 쉐도잉 기법을 사용해 영어를 연습합니다.
매일 15~30분 꾸준히 연습하면 IELTS 스피킹에 대한 자신감이 길러집니다.
쉐도잉이란? 영어 실력을 빠르게 키우는 과학적 방법
쉐도잉(Shadowing)은 원래 전문 통역사 훈련을 위해 개발된 언어 학습 기법으로, 다언어 학자인 Dr. Alexander Arguelles에 의해 대중화된 방법입니다. 핵심 원리는 간단하지만 매우 강력합니다: 원어민의 영어를 들으면서 1~2초의 짧은 지연으로 즉시 소리 내어 따라 말하는 것——마치 '그림자(shadow)'처럼 화자를 따라가는 것입니다. 문법 공부나 수동적인 청취와 달리, 쉐도잉은 뇌와 입 근육이 동시에 실시간으로 영어를 처리하고 재현하도록 훈련합니다. 연구에 따르면 이 방법은 발음 정확도, 억양, 리듬, 연음, 청취력, 말하기 유창성을 크게 향상시킵니다. IELTS 스피킹 준비와 자연스러운 영어 소통을 원하는 분들에게 특히 효과적입니다.