<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" 
     xmlns:content="http://purl.org/rss/1.0/modules/content/"
     xmlns:wfw="http://wellformedweb.org/CommentAPI/"
     xmlns:dc="http://purl.org/dc/elements/1.1/"
     xmlns:meneame="http://meneame.net/faq-es.php"
 >
<channel>
	<title>Menéame: comentarios [3610211]</title>
	<link>http://www.meneame.net</link>
	<image><title>www.meneame.net</title><link>http://www.meneame.net</link><url>http://cdn.mnmstatic.net/img/mnm/eli-rss.png</url></image>
	<description>Sitio colaborativo de publicación y comunicación entre blogs</description>
	<pubDate>Sun, 16 Jan 2022 11:59:00 +0000</pubDate>
	<generator>http://blog.meneame.net/</generator>
	<language>es</language>
	<item>
		<meneame:comment_id>34763441</meneame:comment_id>
		<meneame:link_id>3610211</meneame:link_id>
		<meneame:order>10</meneame:order>
		<meneame:user>meneandro</meneame:user>
		<meneame:votes>1</meneame:votes>
		<meneame:karma>22</meneame:karma>
		<meneame:url>https://www.meneame.net/story/sysjoker-nuevo-backdoor-windows-macos-linux-paso-desapercibido</meneame:url>
		<title>#10 Sysjoker, nuevo backdoor para Windows, macOS y Linux pasó desapercibido hasta ahora [ING]</title>
		<link>https://www.meneame.net/story/sysjoker-nuevo-backdoor-windows-macos-linux-paso-desapercibido/c010#c-10</link>
		<pubDate>Sun, 16 Jan 2022 11:59:00 +0000</pubDate>
		<dc:creator>meneandro</dc:creator>
		<guid>https://www.meneame.net/story/sysjoker-nuevo-backdoor-windows-macos-linux-paso-desapercibido/c010#c-10</guid>
		<description><![CDATA[<p><a class="tooltip c:3610211-9" href="https://www.meneame.net/story/sysjoker-nuevo-backdoor-windows-macos-linux-paso-desapercibido/c09#c-9" rel="nofollow">#9</a> Hasta donde yo entiendo, si que lo hace. Aprovecha para colarse en el sistema con privilegios como un fichero de actualización del repo npm o de streaming (con firma incluída, para que sea validado) y a partir de ahí &#34;The backdoor generates its control-server domain by decoding a string retrieved from a text file hosted on Google Drive&#34;, según el sistema abre puertas de una manera u otra.<br />
<br />
&#60;&#60;Based on organizations targeted and the malware’s behavior, Intezer's assessment is that SysJoker is after specific targets, most likely with the goal of “espionage together with lateral movement which might also lead to a ransomware attack as one of the next stages.”&#62;&#62;</p><p>&#187;&nbsp;autor: <strong>meneandro</strong></p>]]></description>
	</item>

	<item>
		<meneame:comment_id>34763139</meneame:comment_id>
		<meneame:link_id>3610211</meneame:link_id>
		<meneame:order>9</meneame:order>
		<meneame:user>zancudo</meneame:user>
		<meneame:votes>3</meneame:votes>
		<meneame:karma>31</meneame:karma>
		<meneame:url>https://www.meneame.net/story/sysjoker-nuevo-backdoor-windows-macos-linux-paso-desapercibido</meneame:url>
		<title>#9 Sysjoker, nuevo backdoor para Windows, macOS y Linux pasó desapercibido hasta ahora [ING]</title>
		<link>https://www.meneame.net/story/sysjoker-nuevo-backdoor-windows-macos-linux-paso-desapercibido/c09#c-9</link>
		<pubDate>Sun, 16 Jan 2022 11:13:14 +0000</pubDate>
		<dc:creator>zancudo</dc:creator>
		<guid>https://www.meneame.net/story/sysjoker-nuevo-backdoor-windows-macos-linux-paso-desapercibido/c09#c-9</guid>
		<description><![CDATA[<p>El artículo parece algo sensacionalista o yo me estoy perdiendo algo, no es un <i>backdoor</i> en ninguno de los tres sistemas operativos, es básicamente <i>malware </i>que te tienes que  descargar para que te afecte y no te tienes que preocupar por el mero uso del sistema operativo. Vamos, que la solución no viene por un parche del sistema operativo, sino porque lo detecten las herramientas antimalware.</p><p>&#187;&nbsp;autor: <strong>zancudo</strong></p>]]></description>
	</item>

	<item>
		<meneame:comment_id>34763082</meneame:comment_id>
		<meneame:link_id>3610211</meneame:link_id>
		<meneame:order>8</meneame:order>
		<meneame:user>Wayfarer</meneame:user>
		<meneame:votes>3</meneame:votes>
		<meneame:karma>38</meneame:karma>
		<meneame:url>https://www.meneame.net/story/sysjoker-nuevo-backdoor-windows-macos-linux-paso-desapercibido</meneame:url>
		<title>#8 Sysjoker, nuevo backdoor para Windows, macOS y Linux pasó desapercibido hasta ahora [ING]</title>
		<link>https://www.meneame.net/story/sysjoker-nuevo-backdoor-windows-macos-linux-paso-desapercibido/c08#c-8</link>
		<pubDate>Sun, 16 Jan 2022 11:04:02 +0000</pubDate>
		<dc:creator>Wayfarer</dc:creator>
		<guid>https://www.meneame.net/story/sysjoker-nuevo-backdoor-windows-macos-linux-paso-desapercibido/c08#c-8</guid>
		<description><![CDATA[<p><a class="tooltip c:3610211-6" href="https://www.meneame.net/story/sysjoker-nuevo-backdoor-windows-macos-linux-paso-desapercibido/c06#c-6" rel="nofollow">#6</a> &#34;Fuera de un sandbox propiamente aislado&#34;, añadiría.<br />
<br />
CC <a class="tooltip c:3610211-5" href="https://www.meneame.net/story/sysjoker-nuevo-backdoor-windows-macos-linux-paso-desapercibido/c05#c-5" rel="nofollow">#5</a></p><p>&#187;&nbsp;autor: <strong>Wayfarer</strong></p>]]></description>
	</item>

	<item>
		<meneame:comment_id>34761887</meneame:comment_id>
		<meneame:link_id>3610211</meneame:link_id>
		<meneame:order>7</meneame:order>
		<meneame:user>perrico</meneame:user>
		<meneame:votes>1</meneame:votes>
		<meneame:karma>24</meneame:karma>
		<meneame:url>https://www.meneame.net/story/sysjoker-nuevo-backdoor-windows-macos-linux-paso-desapercibido</meneame:url>
		<title>#7 Sysjoker, nuevo backdoor para Windows, macOS y Linux pasó desapercibido hasta ahora [ING]</title>
		<link>https://www.meneame.net/story/sysjoker-nuevo-backdoor-windows-macos-linux-paso-desapercibido/c07#c-7</link>
		<pubDate>Sun, 16 Jan 2022 07:19:09 +0000</pubDate>
		<dc:creator>perrico</dc:creator>
		<guid>https://www.meneame.net/story/sysjoker-nuevo-backdoor-windows-macos-linux-paso-desapercibido/c07#c-7</guid>
		<description><![CDATA[<p><a class="tooltip c:3610211-1" href="https://www.meneame.net/story/sysjoker-nuevo-backdoor-windows-macos-linux-paso-desapercibido/c01#c-1" rel="nofollow">#1</a> Yo también uso Debian<br />
Enviado desde:<br />
<sub>PRETTY_NAME=&#34;Debian GNU/Linux 11 (bullseye)&#34;<br />
NAME=&#34;Debian GNU/Linux&#34;<br />
VERSION_ID=&#34;11&#34;<br />
VERSION=&#34;11 (bullseye)&#34;<br />
VERSION_CODENAME=bullseye<br />
ID=debian<br />
HOME_URL=&#34;<a href="https://www.debian.org/&quot" title="www.debian.org/&quot" rel="nofollow">www.debian.org/&quot</a>;<br />
SUPPORT_URL=&#34;<a href="https://www.debian.org/support&quot" title="www.debian.org/support&quot" rel="nofollow">www.debian.org/support&quot</a>;<br />
BUG_REPORT_URL=&#34;<a href="https://bugs.debian.org/&quot" title="bugs.debian.org/&quot" rel="nofollow">bugs.debian.org/&quot</a>;</sub></p><p>&#187;&nbsp;autor: <strong>perrico</strong></p>]]></description>
	</item>

	<item>
		<meneame:comment_id>34761617</meneame:comment_id>
		<meneame:link_id>3610211</meneame:link_id>
		<meneame:order>6</meneame:order>
		<meneame:user>xiscosoft</meneame:user>
		<meneame:votes>2</meneame:votes>
		<meneame:karma>28</meneame:karma>
		<meneame:url>https://www.meneame.net/story/sysjoker-nuevo-backdoor-windows-macos-linux-paso-desapercibido</meneame:url>
		<title>#6 Sysjoker, nuevo backdoor para Windows, macOS y Linux pasó desapercibido hasta ahora [ING]</title>
		<link>https://www.meneame.net/story/sysjoker-nuevo-backdoor-windows-macos-linux-paso-desapercibido/c06#c-6</link>
		<pubDate>Sun, 16 Jan 2022 01:59:20 +0000</pubDate>
		<dc:creator>xiscosoft</dc:creator>
		<guid>https://www.meneame.net/story/sysjoker-nuevo-backdoor-windows-macos-linux-paso-desapercibido/c06#c-6</guid>
		<description><![CDATA[<p><a class="tooltip c:3610211-5" href="https://www.meneame.net/story/sysjoker-nuevo-backdoor-windows-macos-linux-paso-desapercibido/c05#c-5" rel="nofollow">#5</a> Los amigos no dejan a sus amigos compilar código de fuentes desconocidas <img data-src="https://cdn.mnmstatic.net/v_149/img/menemojis/36/tongue.png" alt=":-P" title=":-P" width="18" height="18" src="https://cdn.mnmstatic.net/v_149/img/g.gif" class="emoji lazy" /></p><p>&#187;&nbsp;autor: <strong>xiscosoft</strong></p>]]></description>
	</item>

	<item>
		<meneame:comment_id>34761612</meneame:comment_id>
		<meneame:link_id>3610211</meneame:link_id>
		<meneame:order>5</meneame:order>
		<meneame:user>--624466--</meneame:user>
		<meneame:votes>6</meneame:votes>
		<meneame:karma>68</meneame:karma>
		<meneame:url>https://www.meneame.net/story/sysjoker-nuevo-backdoor-windows-macos-linux-paso-desapercibido</meneame:url>
		<title>#5 Sysjoker, nuevo backdoor para Windows, macOS y Linux pasó desapercibido hasta ahora [ING]</title>
		<link>https://www.meneame.net/story/sysjoker-nuevo-backdoor-windows-macos-linux-paso-desapercibido/c05#c-5</link>
		<pubDate>Sun, 16 Jan 2022 01:50:58 +0000</pubDate>
		<dc:creator>--624466--</dc:creator>
		<guid>https://www.meneame.net/story/sysjoker-nuevo-backdoor-windows-macos-linux-paso-desapercibido/c05#c-5</guid>
		<description><![CDATA[<p>Siempre se ha dicho que los postinstall scripts que hacen los gestores de paquetes de los principales lenguajes son muy peligrosos, porque pueden ejecutar código arbitrario con el usuario actual del sistema y compilar código C/C++.<br />
<br />
No estoy seguro, pero me ha sonado a eso (tengo que releerlo mañana e investigar las fuentes).<br />
<br />
Quizá que este código de ejecute en un sandbox con WebAssembly, mejoraría la situación. Lo mismo se estaba planeando con las macros de Rust.</p><p>&#187;&nbsp;autor: <strong>--624466--</strong></p>]]></description>
	</item>

	<item>
		<meneame:comment_id>34761481</meneame:comment_id>
		<meneame:link_id>3610211</meneame:link_id>
		<meneame:order>4</meneame:order>
		<meneame:user>comadrejo</meneame:user>
		<meneame:votes>2</meneame:votes>
		<meneame:karma>30</meneame:karma>
		<meneame:url>https://www.meneame.net/story/sysjoker-nuevo-backdoor-windows-macos-linux-paso-desapercibido</meneame:url>
		<title>#4 Sysjoker, nuevo backdoor para Windows, macOS y Linux pasó desapercibido hasta ahora [ING]</title>
		<link>https://www.meneame.net/story/sysjoker-nuevo-backdoor-windows-macos-linux-paso-desapercibido/c04#c-4</link>
		<pubDate>Sun, 16 Jan 2022 00:36:42 +0000</pubDate>
		<dc:creator>comadrejo</dc:creator>
		<guid>https://www.meneame.net/story/sysjoker-nuevo-backdoor-windows-macos-linux-paso-desapercibido/c04#c-4</guid>
		<description><![CDATA[<p><a class="tooltip c:3610211-1" href="https://www.meneame.net/story/sysjoker-nuevo-backdoor-windows-macos-linux-paso-desapercibido/c01#c-1" rel="nofollow">#1</a> La implementación linux solo funciona en algunas versiones rhel.<br />
<br />
<a href="https://www.intezer.com/blog/malware-analysis/vermilionstrike-reimplementation-cobaltstrike/" title="www.intezer.com/blog/malware-analysis/vermilionstrike-reimplementation-cobaltstrike/" rel="nofollow">www.intezer.com/blog/malware-analysis/vermilionstrike-reimplementation</a><br />
<a href="https://www.intezer.com/blog/malware-analysis/new-backdoor-sysjoker/" title="www.intezer.com/blog/malware-analysis/new-backdoor-sysjoker/" rel="nofollow">www.intezer.com/blog/malware-analysis/new-backdoor-sysjoker/</a></p><p>&#187;&nbsp;autor: <strong>comadrejo</strong></p>]]></description>
	</item>

	<item>
		<meneame:comment_id>34761406</meneame:comment_id>
		<meneame:link_id>3610211</meneame:link_id>
		<meneame:order>3</meneame:order>
		<meneame:user>ronko</meneame:user>
		<meneame:votes>2</meneame:votes>
		<meneame:karma>14</meneame:karma>
		<meneame:url>https://www.meneame.net/story/sysjoker-nuevo-backdoor-windows-macos-linux-paso-desapercibido</meneame:url>
		<title>#3 Sysjoker, nuevo backdoor para Windows, macOS y Linux pasó desapercibido hasta ahora [ING]</title>
		<link>https://www.meneame.net/story/sysjoker-nuevo-backdoor-windows-macos-linux-paso-desapercibido/c03#c-3</link>
		<pubDate>Sun, 16 Jan 2022 00:01:54 +0000</pubDate>
		<dc:creator>ronko</dc:creator>
		<guid>https://www.meneame.net/story/sysjoker-nuevo-backdoor-windows-macos-linux-paso-desapercibido/c03#c-3</guid>
		<description><![CDATA[<p><a class="tooltip c:3610211-1" href="https://www.meneame.net/story/sysjoker-nuevo-backdoor-windows-macos-linux-paso-desapercibido/c01#c-1" rel="nofollow">#1</a>  Desde que existe lo del Windows linux subsystem, eso que pones es posible.</p><p>&#187;&nbsp;autor: <strong>ronko</strong></p>]]></description>
	</item>

	<item>
		<meneame:comment_id>34760704</meneame:comment_id>
		<meneame:link_id>3610211</meneame:link_id>
		<meneame:order>2</meneame:order>
		<meneame:user>antoniosoyo</meneame:user>
		<meneame:votes>3</meneame:votes>
		<meneame:karma>31</meneame:karma>
		<meneame:url>https://www.meneame.net/story/sysjoker-nuevo-backdoor-windows-macos-linux-paso-desapercibido</meneame:url>
		<title>#2 Sysjoker, nuevo backdoor para Windows, macOS y Linux pasó desapercibido hasta ahora [ING]</title>
		<link>https://www.meneame.net/story/sysjoker-nuevo-backdoor-windows-macos-linux-paso-desapercibido/c02#c-2</link>
		<pubDate>Sat, 15 Jan 2022 21:13:18 +0000</pubDate>
		<dc:creator>antoniosoyo</dc:creator>
		<guid>https://www.meneame.net/story/sysjoker-nuevo-backdoor-windows-macos-linux-paso-desapercibido/c02#c-2</guid>
		<description><![CDATA[<p>Alguno del MIT haciendo el TFG</p><p>&#187;&nbsp;autor: <strong>antoniosoyo</strong></p>]]></description>
	</item>

	<item>
		<meneame:comment_id>34760248</meneame:comment_id>
		<meneame:link_id>3610211</meneame:link_id>
		<meneame:order>1</meneame:order>
		<meneame:user>mecha</meneame:user>
		<meneame:votes>10</meneame:votes>
		<meneame:karma>85</meneame:karma>
		<meneame:url>https://www.meneame.net/story/sysjoker-nuevo-backdoor-windows-macos-linux-paso-desapercibido</meneame:url>
		<title>#1 Sysjoker, nuevo backdoor para Windows, macOS y Linux pasó desapercibido hasta ahora [ING]</title>
		<link>https://www.meneame.net/story/sysjoker-nuevo-backdoor-windows-macos-linux-paso-desapercibido/c01#c-1</link>
		<pubDate>Sat, 15 Jan 2022 19:51:26 +0000</pubDate>
		<dc:creator>mecha</dc:creator>
		<guid>https://www.meneame.net/story/sysjoker-nuevo-backdoor-windows-macos-linux-paso-desapercibido/c01#c-1</guid>
		<description><![CDATA[<p>Menos mal que yo uso Debian, que tranquilo me quedo.<br />
<br />
<sub>Enviado desde mi Windows 10.</sub></p><p>&#187;&nbsp;autor: <strong>mecha</strong></p>]]></description>
	</item>

</channel>
</rss>
