xzbot

notes, honeypot, and exploit demo for the xz backdoor (CVE-2024-3094) (by amlweems)

Xzbot Alternatives

Similar projects and alternatives to xzbot

NOTE: The number of mentions on this list indicates mentions on common posts plus user suggested alternatives. Hence, a higher number means a better xzbot alternative or higher similarity.

xzbot reviews and mentions

Posts with mentions or reviews of xzbot. We have used some of these posts to build our list of alternatives and similar projects. The last one was on 2024-04-01.
  • Xzbot: Notes, honeypot, and exploit demo for the xz backdoor (CVE-2024-3094)
    6 projects | news.ycombinator.com | 1 Apr 2024
    Instead of needing the honeypot openssh.patch at compile-time https://github.com/amlweems/xzbot/blob/main/openssh.patch

    How did the exploit do this at runtime?

    I know the chain was:

    opensshd -> systemd for notifications -> xz included as transient dependency

    How did liblzma.so.5.6.1 hook all the way back to openssh_RSA_verify when it was loaded into memory?

Stats

Basic xzbot repo stats
2
3,435
2.8
29 days ago

The primary programming language of xzbot is Go.


Sponsored
SaaSHub - Software Alternatives and Reviews
SaaSHub helps you find the best software and product alternatives
www.saashub.com