Skip to content
KitploitKITPLOIT
工具博客
提交
工具博客
提交

黑客、渗透测试和网络安全工具,武装您的安全武器库!

Kitploit 是一个黑客、网络安全和渗透测试工具的目录。发现最新的项目更新,查找漏洞、分析系统、自动化测试并加强你的安全。

··订阅源·联系·隐私·© 2026 Kitploit

工具目录

分类

查看所有分类
Loading categories
CVE-2024-3094-info — CVE-2024-3094 的相关信息 | Kitploit
工具/GitHubGitHub/byinarie/cve-2024-3094-info
漏洞分析漏洞利用恶意软件分析威胁情报供应链安全论文与研究学习与教育事件响应精选资源
GitHubbyinarie/cve-2024-3094-info

CVE-2024-3094-info

CVE-2024-3094 的相关信息

查看仓库
54972年前Kitploit 审核通过

最受欢迎

查看全部 →

发现我们社区最常用的工具。

探索所有工具

浏览我们的工具集合

查看所有工具 →
分享

CVE-2024-3094-info

  • CVE-2024-3094 PoC 探索 https://github.com/amlweems/xzbot

  • https://github.com/lockness-Ko/xz-vulnerable-honeypot

  • https://tukaani.org/xz-backdoor/ - Lasse Collin 的回应

  • https://gist.github.com/thesamesam/223949d5a074ebc3dce9ee78baad9e27

  • https://www.thestack.technology/xz-utils-github-repository-disabled-as-linux-maintainers-assess-blast-radius-of-backdoor-earlier-commits/

  • https://www.reddit.com/r/linux/comments/1brhlur/xz_utils_backdoor/

  • https://gist.github.com/smx-smx/a6112d54777845d389bd7126d6e9f504

CVE-2024-3094 的相关信息

Red Hat 今天针对 Fedora 41 和 Fedora Rawhide 用户发布了关于 XZ 的“紧急安全警报”。没错,就是这种压缩格式的 XZ 工具和库。XZ 5.6.0/5.6.1 中被添加了某些恶意代码,可能允许未经授权的远程系统访问。

Red Hat 因恶意代码进入代码库而将此 XZ 安全漏洞标记为 CVE-2024-3094。我还没有看到 CVE-2024-3094 公开披露,但 Red Hat 安全警报将其总结为: “xz 5.6.0 和 5.6.1 库中存在的恶意注入代码经过混淆处理,且仅在下载包中完整包含——Git 发行版缺少触发恶意代码构建的 M4 宏。如果恶意 M4 宏存在,Git 仓库中的第二阶段工件会在构建时被注入。

由此产生的恶意构建会通过 systemd 干扰 sshd 中的身份验证。SSH 是远程连接系统的常用协议,而 sshd 是提供访问权限的服务。在适当的情况下,这种干扰可能使恶意行为者绕过 sshd 身份验证,并远程获得对整个系统的未经授权访问。”

  • https://isc.sans.edu/podcastdetail/8918

后门逆向分析

  • https://bsky.app/profile/did:plc:x2nsupeeo52oznrmplwapppl/post/3kowjkx2njy2b

在发行版中植入后门的社会工程尝试

  • https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1067708
下载工具
  • https://news.ycombinator.com/item?id=39866275
  • GitHub 仓库(现已禁用)

    • https://github.com/tukaani-project/xz

    各发行版的声明

    • https://www.kali.org/blog/about-the-xz-backdoor/
    • https://archlinux.org/news/the-xz-package-has-been-backdoored/
    • https://access.redhat.com/security/cve/CVE-2024-3094
    • https://bugs.gentoo.org/928134
    • https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1068024
    杂项
    • https://xeiaso.net/notes/2024/xz-vuln/

    • https://www.mail-archive.com/[email protected]/msg00571.html

    • https://nvd.nist.gov/vuln/detail/CVE-2024-3094

    • https://linuxsecurity.com/advisories/debian/debian-dsa-5649-1-xz-utils-security-update-miwy4lbzklq4

    • https://lists.debian.org/debian-security-announce/2024/msg00057.html

    • https://www.redhat.com/en/blog/urgent-security-alert-fedora-41-and-rawhide-users

    • https://www.phoronix.com/news/XZ-CVE-2024-3094

    • https://www.openwall.com/lists/oss-security/2024/03/29/4

    • https://www.virustotal.com/gui/file/13d2a7961d5b7142cc4666f1997b0738d3bc4df904814febfed5c68c29e485d4/detection

    • https://www.reddit.com/r/linux/comments/1bqt999/backdoor_in_upstream_xzliblzma_leading_to_ssh/

    • https://www.reddit.com/r/sysadmin/comments/1bqu3zx/backdoor_in_upstream_xzliblzma_leading_to_ssh/

    • https://www.sdxcentral.com/articles/reported-supply-chain-compromise-affecting-xz-utils-data-compression-library-cve-2024-3094/2024/03/

    • https://linuxsecurity.com/advisories/debian/debian-dsa-5649-1-xz-utils-security-update-miwy4lbzklq4

    • https://en.wikipedia.org/wiki/XZ_Utils