cultural reviewer and dabbler in stylistic premonitions

  • 29 Posts
  • 71 Comments
Joined 3 years ago
cake
Cake day: January 17th, 2022

help-circle





  • That pin can be found for $30 or $35 on on ebay here and here, where it is described as being from the 80s and as an “employee pin”.

    I was thinking that this might have been something aimed specifically at technology buyers in US schools in the 80s or 90s, to whom Apple offered substantial institutional discounts in a (relatively successful) effort to dominate that sector. However searching the phrase “does more costs less” i found this TV spot advertising the Quadra 605 which at $1000 was the cheapest computer Apple sold when it was introduced in October 1993 (and allegedly cheaper than something else they refer to as “PC Leading Brand” 😂). That system was sold under the LC and Performa brands up to 1996, but it was only sold as a Quadra until October 1994, so, to answer OP’s question: that slogan was in use at least sometime in that year.




















  • xzbot from Anthony Weems enables to patch the corrupted liblzma to change the private key used to compare it to the signed ssh certificate, so adding this to your instructions might enable me to demonstrate sshing into the VM :)

    Fun :)

    Btw, instead of installing individual vulnerable debs as those kali instructions I linked to earlier suggest, you could also point debootstrap at the snapshot service so that you get a complete system with everything as it would’ve been in late March and then run that in a VM… or in a container. You can find various instructions for creating containers and VMs using debootstrap (eg, this one which tells you how to run a container with systemd-nspawn; but you could also do it with podman or docker or lxc). When the instructions tell you to run debootstrap, you just want to specify a snapshot URL like https://snapshot.debian.org/archive/debian/20240325T212344Z/ in place of the usual Debian repository url (typically https://deb.debian.org/debian/).


  • A daily ISO of Debian testing or Ubuntu 24.04 (noble) beta from prior to the first week of April would be easiest, but those aren’t archived anywhere that I know of. It didn’t make it in to any stable releases of any Debian-based distros.

    But even when you have a vulnerable system running sshd in a vulnerable configuration, you can’t fully demo the backdoor because it requires the attacker to authenticate with their private key (which has not been revealed).

    But, if you just want to run it and observe the sshd slowness that caused the backdoor to be discovered, here are instructions for installing the vulnerable liblzma deb from snapshot.debian.org.