Solved CVE-2024-3094: Detecting the SSHD backdoor in XZ Utils

Status
Not open for further replies.

hald9000

Bronze Partner
Advanced Certified
Joined
Jun 18, 2022
Messages
48
Reaction score
13
Do we have to worry about this SSH backdoor issue with the 3CX v18 or v20 provided Debian ISOs for Linux?

Present I provide my own cloud for my clients; however, I am testing one customer on 3CX Hosting Services.

My familiarity is more on the Windows side of things; however, I can get around fairly good on Linux. However, my security skills are not as strong so what about after installing SSH. I generally install 3CX in the Hyper-V Virtual Machine at present so it's more likely I use the Hyper-V Virtual Console.

As the phone system is mission critical for my customers; I am going to say on v18 for a bit longer until v20 Update 2 arrives.
 
Last edited:
I wanted to inform you that we are already looking into the matter although at the current state it seems that is not affecting Debian installation. We will share additional details once available.
 
While waiting on 3CX to double confirm... When reading the posting below it appears that the discovery by a Linux Community Member has prevented the issue from being incorporated into any production releases for the major Linux distributions, however, Debian Testing environments may have to be looked at IF you do very early Linux testing. When I first saw this, this could have been a major whoopsie daisy -- but it is good thing that appears NOT to be the case.

by DAN GOODIN - 3/29/2024, 2:50 PM
at Ars Technica

"The compression utility, known as xz Utils, introduced the malicious code in versions 5.6.0 and 5.6.1, according to Andres Freund, the developer who discovered it. There are no known reports of those versions being incorporated into any production releases for major Linux distributions, but both Red Hat and Debian reported that recently published beta releases used at least one of the backdoored versions—specifically, in Fedora Rawhide and Debian testing, unstable and experimental distributions. A stable release of Arch Linux is also affected. That distribution, however, isn't used in production systems.

Because the backdoor was discovered before the malicious versions of xz Utils were added to production versions of Linux, “it's not really affecting anyone in the real world,” Will Dormann, a senior vulnerability analyst at security firm Analygence, said in an online interview. “BUT that's only because it was discovered early due to bad actor sloppiness. Had it not been discovered; it would have been catastrophic to the world."

Several people, including two Ars readers, reported that the multiple apps included in the HomeBrew package manager for macOS rely on the backdoored 5.6.1 version of xz Utils. HomeBrew has now rolled back the utility to version 5.4.6."
 
Last edited:
  • Like
Reactions: Evolute IT
Hi,

Our repository does not contain the affected versions. (We avoid including experimental/testing versions anyway.)

The V20 repo includes 5.4.1-0.2 and the V18 one 5.2.4-1.

The 3CX ISO also does not use Debian's testing or unstable repositories.

Additionally we don't push packages to our public repository without first being rigorously tested so even if it was released in Debian's stable repository we wouldn't just immediately push it to ours. Especially given that it wouldn't be a security update. But yes, fortunately this was caught early on before it made it to the stable repo, even though it seems the campaign had started a very long time ago in an attempt to fly under the radar.
 
While I originally was focused on the ISO; may I assume the same goes for 3CX Hosted Platform.

I want to thank you for everything that you are helping with as a CNO, as an MSP I understand... I guess the watch word is "vigilance".
 
While I originally was focused on the ISO; may I assume the same goes for 3CX Hosted Platform.
Yes that is correct.

I want to thank you for everything that you are helping with as a CNO, as an MSP I understand... I guess the watch word is "vigilance".
Thanks for your nice words! You are absolutely correct. Remaining vigilant against the latest threats is a neccesity. The 3CX team and I are doing our best to keep an eye on the latest development on all fronts. Cybersecurity is an ever evolving dynamic landscape. You can’t blink : )
 
After viewing the details here, it is very important to check the details of file hashes after operations. Another, key thing we could do after installation is monitor File Hash auditing of the files in the OS. This could be indispensable given the number of Linux systems that 3CX supports via its partners, customers or its own hosted platform.

Since, we don't update Linux outside of what the 3CX ISO provides it should be known what files are present and correct.

Some kind of File Integrity Monitoring (FIM) platform could we add to focus the system. I am new to LInux BTW; does auditd help?
 
I am afraid we can't advise/consult on specifics about your infrastructure.

Generally, before evaluating different software/solutions it would be good to make sure the basics are done first. Don't install third party software on your server unless absolutely necessary. Follow the principle of least privilege, lock down access to the server/admin areas only to specific people/ips. Don't expose SSH/RDP or any other services that are low hanging fruit. Ensure the O.S/software is always up to update with the latest stable releases. Use unique strong passwords and 2FA/MFA wherever possible and rotate them frequently. These are some of the actions required that provide a "good" baseline. There are many online resources to familiarize yourself with Linux, hardening and/or the different aspects of security. Before taking any action or making any changes make sure you first have a solid understanding of the mechanics behind each change.

As the initial question/concern has been addressed, I will go ahead and close the topic.
 
Status
Not open for further replies.

Members Online Now

Forum statistics

Threads
111,825
Messages
589,243
Members
164,655
Latest member
Avrion Operations