Stories
Slash Boxes
Comments

SoylentNews is people

posted by mrpg on Thursday July 12 2018, @09:40AM   Printer-friendly
from the allows-anyone-to-take-over dept.

Submitted via IRC for Fnord666

[...] Malware has been discovered in at least three Arch Linux packages available on AUR (Arch User Repository), the official Arch Linux repository of user-submitted packages.

[...] The incident happened because AUR allows anyone to take over "orphaned" repositories that have been abandoned by their original authors.

[...] According to a Git commit to the package's source code, xeactor added malicious code that would download a file named "~x" from ptpb.pw, a lightweight site mimicking Pastebin that allows users to share small pieces of texts.

[...] Besides downloading ~u, the main purpose of the first file (~x) was also to modify systemd and add a timer to run the ~u file at every 360 seconds.

[...] No other malicious actions were observed, meaning the acroread package wasn't harming users' systems, but merely collecting data in preparation for... something else.

Source: Malware Found in Arch Linux AUR Package Repository


Original Submission

 
This discussion has been archived. No new comments can be posted.
Display Options Threshold/Breakthrough Mark All as Read Mark All as Unread
The Fine Print: The following comments are owned by whoever posted them. We are not responsible for them in any way.
  • (Score: 5, Funny) by takyon on Thursday July 12 2018, @04:33PM (6 children)

    by takyon (881) <takyonNO@SPAMsoylentnews.org> on Thursday July 12 2018, @04:33PM (#706257) Journal

    Switch to Microsoft Windows Linux [wikipedia.org], bro. It's got this new and improved "closed source" security model. Check it out!

    --
    [SIG] 10/28/2017: Soylent Upgrade v14 [soylentnews.org]
    Starting Score:    1  point
    Moderation   +3  
       Funny=3, Total=3
    Extra 'Funny' Modifier   0  
    Karma-Bonus Modifier   +1  

    Total Score:   5  
  • (Score: 3, Insightful) by DannyB on Thursday July 12 2018, @05:27PM (1 child)

    by DannyB (5839) Subscriber Badge on Thursday July 12 2018, @05:27PM (#706276) Journal

    The bad thing about WSL is that it is Microsoft Linux. So you use WSL and develop your Linux application. You go to deploy it in production on genuine Linux and it doesn't work due to some subtle incompatibility. "Oh, well" management says "we'll just deploy it on Windows in production."

    --
    The anti vax hysteria didn't stop, it just died down.
    • (Score: 0) by Anonymous Coward on Friday July 13 2018, @01:42AM

      by Anonymous Coward on Friday July 13 2018, @01:42AM (#706444)

      That happened to you? Or whom?

  • (Score: 2, Interesting) by realDonaldTrump on Thursday July 12 2018, @10:53PM (3 children)

    by realDonaldTrump (6614) on Thursday July 12 2018, @10:53PM (#706394) Homepage Journal

    Great company, one of the biggest. And maybe they can help us close up that internet too. We're losing so many people to internet!

    • (Score: 2) by Runaway1956 on Friday July 13 2018, @02:54PM (2 children)

      by Runaway1956 (2926) Subscriber Badge on Friday July 13 2018, @02:54PM (#706643) Homepage Journal

      Babbling again? WTF did you just say? No - forget that. WTF did you mean?

      --
      Abortion is the number one killed of children in the United States.
      • (Score: 2) by realDonaldTrump on Friday July 13 2018, @03:44PM (1 child)

        by realDonaldTrump (6614) on Friday July 13 2018, @03:44PM (#706656) Homepage Journal

        Microsoft, one of our great cyber companies, one of the biggest. They have made tremendous progress and the future of the Microsoft is very bright. Especially since they got .@BillGates [twitter.com] out as Chairman. Now they're doing "'closed source' security." And we want that for our internet, to help close up our internet. We have ISIS on our internet, we have sex traffickers on our internet. And we're losing many people. China closed up their internet (Golden Shield) and it's been PERFECTO for them. And we're moving very strongly on that one. Very strongly!

        • (Score: 2) by Runaway1956 on Friday July 13 2018, @04:18PM

          by Runaway1956 (2926) Subscriber Badge on Friday July 13 2018, @04:18PM (#706676) Homepage Journal

          Uhhh, ohkay - you're some kind of gullible fool.

          Did you know that Microsoft operating systems are unique? All OTHER operating systems were built on top of security. That is, everything is owned by someone, whether it be root, or a user, or SYSTEM - everything is owned, and no one can take it, or use it. Microsoft? Everything that passes for "security" is just bolted on, as an after thought.

          Microsoft security is an oxymoron, just like military intelligence.

          --
          Abortion is the number one killed of children in the United States.