• 56!
    arrow-up
    24
    arrow-down
    0
    ·
    7 months ago
    link
    fedilink

    I’m on Void, and I had the malicious version installed. Updating the system downgraded xz to 5.4.6, so it seems they are on it. I’ll be watching discussions to decide if my system might still be compromised.

    • AuliEnglish
      arrow-up
      1
      arrow-down
      0
      ·
      7 months ago
      link
      fedilink

      Did you have SSH open to the internet?

      • 56!
        arrow-up
        2
        arrow-down
        0
        ·
        7 months ago
        link
        fedilink

        No, this is just my personal laptop. I don’t even have access to an IP address I could enable port-forwarding on.

      • arouene
        arrow-up
        1
        arrow-down
        0
        ·
        7 months ago
        link
        fedilink

        @Auli @56_ I have SSH open on internet on ipv6, I’m safe. Do you think VPN open on the internet is safer ? (Think twice CVE-2024-21762)

    • Possibly linuxEnglish
      arrow-up
      1
      arrow-down
      1
      ·
      7 months ago
      link
      fedilink

      I would nuke it and rebuild. If nothing else it is a good test of backups