• boredsquirrel
    link
    fedilink
    arrow-up
    7
    ·
    26 days ago

    Yes and if viruses use something like base64 encoding or other methods, the hashes dont match anymore.

    As far as I understood it, it is pretty easy to make your virus permanently un-hashable by just always changing some bits

    • atzanteol@sh.itjust.works
      link
      fedilink
      English
      arrow-up
      2
      ·
      26 days ago

      The xz backdoor was a packaged file distributed with the standard packages though. It would be trivial to find.

      • boredsquirrel
        link
        fedilink
        arrow-up
        1
        ·
        26 days ago

        This is obviously not about this known file.

        It is about “would this scanner detect a system package from the official repos opening an ssh connection”