An attempt to create a backdoor in Linux

General support questions
odysseus
Posts: 69
Joined: 2014/09/14 16:55:22

An attempt to create a backdoor in Linux

Post by odysseus » 2018/12/14 06:45:56

Hi,

just wishing you a merry christmas and a happy new year, by presenting to
you a new trojan for Linux. It`s professionally made by Apple Computer
Inc. (must be somebody who threatened them to do it).

https://imgur.com/a/UEcm27H

https://imgur.com/a/ocFgssS

User avatar
avij
Retired Moderator
Posts: 3046
Joined: 2010/12/01 19:25:52
Location: Helsinki, Finland
Contact:

Re: An attempt to create a backdoor in Linux

Post by avij » 2018/12/14 06:53:55

I'm afraid I don't see anything evil in that output. Care to clarify?

odysseus
Posts: 69
Joined: 2014/09/14 16:55:22

Re: An attempt to create a backdoor in Linux

Post by odysseus » 2018/12/14 10:43:11

avij wrote:
2018/12/14 06:53:55
I'm afraid I don't see anything evil in that output. Care to clarify?
Here's another proof: https://imgur.com/a/DFqcteW.

User avatar
avij
Retired Moderator
Posts: 3046
Joined: 2010/12/01 19:25:52
Location: Helsinki, Finland
Contact:

Re: An attempt to create a backdoor in Linux

Post by avij » 2018/12/14 10:47:46

odysseus wrote:
2018/12/14 10:43:11
avij wrote:
2018/12/14 06:53:55
I'm afraid I don't see anything evil in that output. Care to clarify?
Here's another proof: https://imgur.com/a/DFqcteW.
That's entirely different from your above post, and is related to differences(/bugs) in various UEFI implementations. There's a bug entry for tracking such UEFI issues.

odysseus
Posts: 69
Joined: 2014/09/14 16:55:22

Re: An attempt to create a backdoor in Linux

Post by odysseus » 2018/12/15 05:47:38

avij wrote:
2018/12/14 10:47:46
odysseus wrote:
2018/12/14 10:43:11
avij wrote:
2018/12/14 06:53:55
I'm afraid I don't see anything evil in that output. Care to clarify?
Here's another proof: https://imgur.com/a/DFqcteW.
That's entirely different from your above post, and is related to differences(/bugs) in various UEFI implementations. There's a bug entry for tracking such UEFI issues.
Programming is over my head, but it looks like Apple has a weird UEFI firmware to connect it to a systemd metadata crawler.

User avatar
avij
Retired Moderator
Posts: 3046
Joined: 2010/12/01 19:25:52
Location: Helsinki, Finland
Contact:

Re: An attempt to create a backdoor in Linux

Post by avij » 2018/12/15 08:22:07

I ... am not sure you are interpreting the output correctly. Maybe you should examine the suspected security issue in more depth before making such claims.

odysseus
Posts: 69
Joined: 2014/09/14 16:55:22

Re: An attempt to create a backdoor in Linux

Post by odysseus » 2018/12/16 02:38:14

avij wrote:
2018/12/15 08:22:07
I ... am not sure you are interpreting the output correctly.
Sure, but this output is extremely bizarre and worrying.

Mike_Rochefort
Posts: 215
Joined: 2016/03/16 02:34:19

Re: An attempt to create a backdoor in Linux

Post by Mike_Rochefort » 2018/12/16 19:25:20

Are you running this on an Apple computer? If so, that may be where this is coming from. Personally, I’ve never seen that output in my life, which makes me think it’s specific to your setup.

Cheers,
Mike
Solution Architect @RedHat | RHCE
Former SysAdmin @BlueSkyStudios and @Pixar
Feature animation and VFX enthusiast
--
Report CentOS Stream 8 bugs: https://da.gd/c8s-bugs
Report CentOS Stream 9 bugs: https://da.gd/c9s-bugs

User avatar
TrevorH
Site Admin
Posts: 33215
Joined: 2009/09/24 10:40:56
Location: Brighton, UK

Re: An attempt to create a backdoor in Linux

Post by TrevorH » 2018/12/16 23:17:44

Given that the hostname in that syslog output appears to be "ok-air" which would be the tail end of macbook-air, I suspect it is.

I'm tempted to lock this whole thread as it appears to me to be a massive troll.
The future appears to be RHEL or Debian. I think I'm going Debian.
Info for USB installs on http://wiki.centos.org/HowTos/InstallFromUSBkey
CentOS 5 and 6 are deadest, do not use them.
Use the FAQ Luke

odysseus
Posts: 69
Joined: 2014/09/14 16:55:22

Re: An attempt to create a backdoor in Linux

Post by odysseus » 2018/12/17 06:26:58

Yes, my hostname is "macbook-air".
Last edited by odysseus on 2019/05/29 08:21:31, edited 1 time in total.

Post Reply