Практика Shadowing: Linux got wrecked by backdoor attack - Изучайте разговорный английский по видео

Создание урока...
1
Over the last few days, the open -source world has been in panic mode.
2
A highly sophisticated and carefully planned attack affecting the XZ compression tool was shipped to production,
3
and has compromised Linux distros like Debian, Kali, OpenSUSE, and others.
4
Thank God, TempleOS is unaffected though, and it's quite possibly one of the most well -executed supply chain attacks of all time,
5
and gives some random dude unfettered access to execute code on your machine via a secret backdoor.
6
This is not your everyday security vulnerability.
7
It's a threat -level midnight 10 .0 critical issue on the CVE Richter scale, even higher than famous bugs like Heartbleed, Log4Shell, and Shellshock.
8
In today's video, you'll learn exactly how the XZ backdoor works, and the incredible story of how it was discovered by accident.
9
It is April 1st, 2024, and you're watching the Code Report.
10
Unfortunately, this is not an April Fool's video.
11
If you happen to be using one of the Linux distros listed here, you'll want to upgrade immediately.
12
Luckily, it only affects a very narrow set of distros, most of which are unstable builds, but that's only because this backdoor was discovered by pure luck early on.
13
More on that in just a second, let's first take a deep dive into this backdoor.
14
XZ -Utils is a tool for compressing and decompressing streams based on the Lempel -Ziv Markov Chain Algorithm, or LZMA.
15
It contains a command line tool that's installed on most Linux distros by default, which you can use right now with the XZ command, but also contains an API library called lib -LZMA,
16
and many other pieces of software depend on this library to implement compression, One of which is SSHD, or Secure Shell Daemon, a tool that listens to SSH connections,
17
like when you connect your local machine to the terminal on a cloud server.
18
Now here's where the backdoor comes in, but keep in mind, researchers are still figuring out exactly how this thing works.
19
Malicious code was discovered in the tarballs of LibLZMA, which is the thing that most people actually install.
20
That malicious code is not present in the source code, though.
21
It uses a series of obfuscations to hide the malicious code, then at build time, it injects a pre -built object disguised as a test file that lives in the source code.
22
It modifies specific parts of the LZMA code, which ultimately allows the attacker to intercept and modify data that interacts with this library.
23
Researchers have also discovered that any payload sent to the backdoor must be signed by the attacker's private key.
24
In other words, the attacker is the only one who can send a payload to the backdoor, making it more difficult to test and monitor.
25
And the attacker went to great lengths to obfuscate the code, like it contains no ASCII characters and instead has a built -in state machine to recognize important strings.
26
Now, because the vast majority of servers that power the internet are Linux -based, this backdoor could have been a major disaster.
27
Luckily, though, a hero software engineer named Andres Freund was using the unstable branch of Debian to benchmark Postgres.
28
He noticed something weird that most people would overlook.
29
SSH logins were using up more CPU resources than normal.
30
Initially, he thought it was an issue in Debian directly, but after some investigation, discovered it was actually upstream in exeutils.
31
And that's really bad, because so many things depend on this tool.
32
In German, his last name translates to friend, which is fitting, because he single -handedly helped the world avoid a multi -billion dollar disaster. But whodunit?
33
Who's the bad guy here?
34
At this point, it's unclear.
35
The LibLZMA project is maintained by Lassie Collin.
36
However, the malicious tarballs are signed by Gia Tan, a contributor to the project.
37
This individual has been a trusted contributor for the last few years, but clearly, they've been playing the long game.
38
They spent years building up trust before trying the backdoor, and nobody even noticed when they made their move.
39
I say they because we don't know if this is an individual or a penetration attempt from a rogue state like Russia, North Korea, or the United States.
40
Here's a non -technical analogy.
41
Imagine there's a landlord, we'll call him Lassie Collin, who manages a popular apartment building.
42
It's a lot of work, but this young, enthusiastic guy has been super helpful over the last couple years, adding all sorts of upgrades and renovations.
43
Let's call him Gia Tan.
44
He does great work, but he's also been secretly installing cameras in the bathrooms, which only he can access from the internet with his password.
45
Now, he would have gotten away with it too if it weren't for a pesky tenant named Andres, who happened to notice that his electricity bill was just a little bit higher than usual.
46
He started looking behind the walls and found some unexpected wires that led right to the unauthorized cameras.
47
At this point, we don't know the true identity of the hacker, but whoever did this was looking to cast a very wide net, and because it's protected by a secret key, can only be exploited by one party.
48
XZ was a sitting duck because it's extremely popular, while also being very boring with a single maintainer.
49
Whoever's behind this is either an extremely intelligent psychopath, or more likely, a group of state -sponsored dimension -hopping lizard people hellbent on world domination.
50
And that's why the only distro you should use is TempleOS.
51
This has been The Code Report, thanks for watching, and I will see you in the next one.

Об этом уроке

Вы практикуете английский с "Linux got wrecked by backdoor attack" с помощью техники Shadowing — метода, разработанного для подготовки профессиональных переводчиков.

Слушайте каждое предложение, обращайте внимание на ударения и связывание звуков, затем повторяйте вслух уверенно. 15–30 минут ежедневной практики дадут заметные результаты.

Что такое техника Shadowing?

Shadowing — это научно обоснованная техника изучения языка, изначально разработанная для подготовки профессиональных переводчиков и популяризированная полиглотом доктором Александром Аргуэльесом. Метод прост, но эффективен: вы слушаете аудио на английском от носителей языка и немедленно повторяете вслух — как тень, следующая за говорящим с задержкой в 1–2 секунды. В отличие от пассивного прослушивания или грамматических упражнений, Shadowing заставляет мозг и мышцы рта одновременно обрабатывать и воспроизводить реальные речевые паттерны. Исследования показывают, что это значительно улучшает точность произношения, интонацию, ритм, связную речь, понимание на слух и беглость речи — что делает его одним из самых эффективных методов для подготовки к IELTS Speaking и реального общения на английском.