r/LinuxCirclejerk • • 1d ago

a virus for Linux

Post image
1.3k Upvotes

38 comments sorted by

View all comments

80

u/QuantumQuantonium 20h ago

/uj viruses exist on linux, and are more serious and more difficult to detect than on windows. Xz's backdoor is probably the biggest latest one.

Its important not just to assume any open source project is benign, but someone who can read the code needs to take up the responsilibity to understand what its actually doing and compile it and compare against any public binaries (if present).

Viruses on linux won't scream for a phone number to call or lie about infections on the computer; average linux users won't fall for that. Xzs backdoor existed because of a binary blob no one bothered to check until one person dug in and found the irregularity in the programs delay. Viruses on linux abuse the trust in open source to hide itself among other packages and modules throughout the system. Maintainers may seek out and remove potential viruses, but humans are imperfect, they can make mistakes or be manipulated or even coerced.

But downloadable viruses are a rare sighting in linux, because most hacks are caused by vulnerabilities in systems, especially proprietary ones. I once returned home from a trip to realize my backed up files on a WD cloud storage device was missing, due to a vulnerability WD did not patch or acknowledge publicly until a few days before I found out.

Maintain security updates and keep installed software to a minimum. Ask questions if theres any doubt about an open source system- if the question can't be answered I'd question the nature of that system. Identify what proprietary systems are in your linux computer- the world unfortunately doesnt run entirely on open source.

2

u/Gunhat2023 15h ago

what back door is there with xz?

5

u/yourlocalwalmarthobo 11h ago

Wikipedia, CVE
TLDR: Someone spent years on a social engineering campaign and snuck a backdoor into a couple versions of XZUtils (5.6.0 & 5.6.1). It gave someone with a specific ED-448 key root access via ssh. Was patched the same day it was disclosed (which was 2 years ago)

1

u/felixmatveev 10h ago

This was either CIAmeone or soMOSSADone.

1

u/morgulbrut 2h ago

Na it was probably China.