Lobsters | 原文链接 | 2026-09-06 收录

信任链攻击不止于编译器:用 GNU strip 对一整个 Linux 发行版植入后门

来源: arxiv.org — 2026-07-27

概述

这篇 arXiv 论文把 Ken Thompson 经典的「信任一切」(trusting-trust)攻击推广到全新领域,证明它根本不只针对编译器。作者用 GNU strip——一个既不检查也不生成源码的普通构建工具——仅靠改写成品 ELF 文件,就在 NixOS 发行版的引导流程里种下 payload,让后门随 strip 的自我重建一代代传播,并在种子退出依赖闭包后仍存活进最终的标准环境。

核心要点

金句

We construct a complete trusting-trust attack around GNU strip, an ordinary build utility that neither inspects nor generates source code, using only manipulations of finished ELF files.
返回 Lobsters 首页