2 comments

  • fisian26 minutes ago
    Discussion at the time: <a href="https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=26591669">https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=26591669</a>
  • bananamogul2 hours ago
    “To be continued.”<p>This was published in 2021 but apparently never continued.
    • normie30001 hour ago
      Cue spooky music.
      • Joel_Mckay1 hour ago
        1. power off using switch<p>2. boot from immutable live system<p>3. sudo mkdir -p &#x2F;mnt&#x2F;sus&#x2F;infected<p>4. sudo ddrescue -d -f &#x2F;dev&#x2F;sda &#x2F;mnt&#x2F;sus&#x2F;sus.img &#x2F;mnt&#x2F;sus&#x2F;sus.log<p>5. sudo kpartx -l &#x2F;mnt&#x2F;sus&#x2F;sus.img<p>6. sudo kpartx -av &#x2F;mnt&#x2F;sus&#x2F;sus.img<p>7. sudo mount -o loop &#x2F;dev&#x2F;mapper&#x2F;loop0p2 &#x2F;mnt&#x2F;sus&#x2F;infected<p>8. sudo debsums -sac -r &#x2F;mnt&#x2F;sus&#x2F;infected<p>9. sudo umount &#x2F;dev&#x2F;mapper&#x2F;loop0p2<p>10. sudo kpartx -d &#x2F;mnt&#x2F;sus&#x2F;sus.img<p>11. Submit infected binaries in zip.vir file for forensic de-compilation, and ascertain how payload was dropped.<p>Every once in a awhile these things happen. Better to redeploy a new clean OS container on the host, and dump the traffic with a remote live packet capture.<p>Repeat as necessary. =3