Hacker News
Read post

decrypt verifies a signature on the server's host key by a fixed Ed448 key, and then passes a payload to system(). It's RCE, not auth bypass, and gated/unreplayable." — Bluesky

A preliminary analysis reveals that the xz backdoor utilizes a fixed Ed448 key to verify the server's host key and then executes a payload through system(), resulting in remote code execution.

    #security#webdev#cryptography#reverse-engineering
Mar 30, 2024•1m read time•From bsky.app
Post cover image
Table of contents
Post
Hacker News's image
Hacker News

Hacker News is a community-driven platform for sharing and discussing technology news, startups, and...

17.4K Followers

•

141.8K Upvotes

Would you recommend this post?

Copy link
WhatsApp
Facebook
X
New Squad
  • © 2026 Daily Dev Ltd.
  • Guidelines
  • Explore
  • Tags
  • Sources
  • Squads
  • Leaderboard