
Un rol de Ansible que instala la puerta trasera xz (CVE-2024-3094) en un host Debian y, opcionalmente, instala la herramienta xzbot.
Un rol de Ansible que instala el xz backdoor (CVE-2024-3094) en un host Debian y, opcionalmente, instala la herramienta xzbot.
[!WARNING] ¡Este rol despliega malware a propósito! Sin exponer el host a internet deberías estar a salvo, pero sigue siendo malware. Ten cuidado.

SO basado en Debian
Las variables disponibles se enumeran a continuación, junto con los valores predeterminados (consulte defaults/main.yml):
# Install the xzbot cli tool used to send commands to the backdoor. It is installed to /usr/bin/xzbot
ludus_xz_backdoor_install_xzbot: true
# Install the xz backdoor library by linking it to liblzma.so.5 used by the system and rebooting
ludus_xz_backdoor_install_backdoor: true
# Remove the backdoor by replacing the symlink to liblzma.so.5 with the original and rebooting
ludus_xz_backdoor_uninstall_backdoor: false
Ninguna.
- hosts: xz_backdoor_hosts
roles:
- badsectorlabs.ludus_xz_backdoor
vars:
ludus_xz_backdoor_install_xzbot: true
ludus_xz_backdoor_install_backdoor: true
ludus:
- vm_name: "{{ range_id }}-xz-backdoor"
hostname: "{{ range_id }}-xz-backdoor"
template: debian-12-x64-server-template
vlan: 10
ip_last_octet: 2
ram_gb: 2
cpus: 2
linux: true
roles:
- badsectorlabs.ludus_xz_backdoor
role_vars:
ludus_xz_backdoor_install_xzbot: true
ludus_xz_backdoor_install_backdoor: true
GPLv3
Este rol fue creado por Bad Sector Labs, para Ludus.