Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Gynvael Coldwind made a great analysis about it: https://gynvael.coldwind.pl/?lang=en&id=782

https://news.ycombinator.com/item?id=39878681

xz/liblzma: Bash-stage Obfuscation Explained



That is, as it says in the title, about the Bash-stage obfuscation. That’s fun but it’d also be interesting to know what capabilities the exploit payload actually provided to the attacker. Last I looked into that a month or so ago there were at least two separate endpoints already discovered, and the investigation was still in progress.




Consider applying for YC's Winter 2026 batch! Applications are open till Nov 10

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: