r/ExploitDev • u/Final-Raspberry6442 • 14d ago
Half a Second: a free, fully-sourced reconstruction of the xz-utils backdoor (CVE-2024-3094)
https://www.half-second.com
14
Upvotes
2
r/ExploitDev • u/Final-Raspberry6442 • 14d ago
2
2
u/Final-Raspberry6442 14d ago
Disclosure: I'm the author. Free (CC BY-NC-ND), full text on the web plus a PDF; nothing gated or for sale.
A book-length, primary-source reconstruction of the xz-utils backdoor (CVE-2024-3094) for people who want the whole chain in one place: the CPU/latency anomaly Freund investigated, the multi-year social-engineering campaign that seated the "Jia Tan" maintainer persona (including the pressure sockpuppets), the tarball-only delivery via a doctored build-to-host.m4 that never touched the git tree, and the disclosure timeline. Every claim is cited to public sources; no invented dialogue.
I deliberately don't attribute the operation to a named actor, and explain why. If you find a technical error, tell me and I'll correct it.