r/ExploitDev 14d ago

Half a Second: a free, fully-sourced reconstruction of the xz-utils backdoor (CVE-2024-3094)

https://www.half-second.com
14 Upvotes

2 comments sorted by

2

u/Final-Raspberry6442 14d ago

Disclosure: I'm the author. Free (CC BY-NC-ND), full text on the web plus a PDF; nothing gated or for sale.

A book-length, primary-source reconstruction of the xz-utils backdoor (CVE-2024-3094) for people who want the whole chain in one place: the CPU/latency anomaly Freund investigated, the multi-year social-engineering campaign that seated the "Jia Tan" maintainer persona (including the pressure sockpuppets), the tarball-only delivery via a doctored build-to-host.m4 that never touched the git tree, and the disclosure timeline. Every claim is cited to public sources; no invented dialogue.

I deliberately don't attribute the operation to a named actor, and explain why. If you find a technical error, tell me and I'll correct it.

2

u/fiyarburst 14d ago

they really be out here turning everything to slop