LinuxQuestions.org
Help answer threads with 0 replies.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - General
User Name
Password
Linux - General This Linux forum is for general Linux questions and discussion.
If it is Linux Related and doesn't seem to fit in any other forum then this is the place.

Notices


Reply
  Search this Thread
Old 12-18-2015, 12:34 PM   #1
onebuck
Moderator
 
Registered: Jan 2005
Location: Central Florida 20 minutes from Disney World
Distribution: SlackwareŽ
Posts: 13,927
Blog Entries: 45

Rep: Reputation: 3159Reputation: 3159Reputation: 3159Reputation: 3159Reputation: 3159Reputation: 3159Reputation: 3159Reputation: 3159Reputation: 3159Reputation: 3159Reputation: 3159
Vulnerability in popular bootloader puts locked-down Linux computers at risk


Hi,

From http://www.csoonline.com/article/301...s-at-risk.html

Quote:
The flaw can allow attackers to modify password-protected boot entries and deploy malware

Pressing the backspace key 28 times can bypass the Grub2 bootloader's password protection and allow a hacker to install malware on a locked-down Linux system.
GRUB, which stands for the Grand Unified Bootloader, is used by most Linux distributions to initialize the operating system when the computer starts. It has a password feature that can restrict access to boot entries, for example on computers with multiple operating systems installed.
This protection is particularly important within organizations, where it is also common to disable CD-ROM, USB and network boot options and to set a password for the BIOS/UEFI firmware in order to secure computers from attackers who might gain physical access to the machines.
Without these boot options secured, attackers or malicious employees could simply boot from an alternative OS -- like a live Linux installation stored on a USB drive or CD/DVD -- and access files on a computer's hard drive
Hope this helps!
 
Old 12-18-2015, 04:30 PM   #2
sgosnell
Senior Member
 
Registered: Jan 2008
Location: Baja Oklahoma
Distribution: Debian Stable and Unstable
Posts: 1,943

Rep: Reputation: 542Reputation: 542Reputation: 542Reputation: 542Reputation: 542Reputation: 542
If you're relying on a grub password to protect your system, you probably believe in the tooth fairy.
 
Old 12-18-2015, 07:44 PM   #3
jefro
Moderator
 
Registered: Mar 2008
Posts: 22,020

Rep: Reputation: 3630Reputation: 3630Reputation: 3630Reputation: 3630Reputation: 3630Reputation: 3630Reputation: 3630Reputation: 3630Reputation: 3630Reputation: 3630Reputation: 3630
The problem has ways been a physical access issue.
 
Old 12-18-2015, 07:59 PM   #4
rokytnji
LQ Veteran
 
Registered: Mar 2008
Location: Waaaaay out West Texas
Distribution: antiX 23, MX 23
Posts: 7,148
Blog Entries: 21

Rep: Reputation: 3483Reputation: 3483Reputation: 3483Reputation: 3483Reputation: 3483Reputation: 3483Reputation: 3483Reputation: 3483Reputation: 3483Reputation: 3483Reputation: 3483
My 5 dogs say come on and try it

My shop stays gaurded and secure. The Harleys are worth more to me than my computers.
I don't expect a geek to show up knowing the grub flaw and bringing a .45 to just hack into my computer.

Besides. Debian already pushed out a fix for this I am pretty sure.
 
Old 12-18-2015, 10:07 PM   #5
onebuck
Moderator
 
Registered: Jan 2005
Location: Central Florida 20 minutes from Disney World
Distribution: SlackwareŽ
Posts: 13,927

Original Poster
Blog Entries: 45

Rep: Reputation: 3159Reputation: 3159Reputation: 3159Reputation: 3159Reputation: 3159Reputation: 3159Reputation: 3159Reputation: 3159Reputation: 3159Reputation: 3159Reputation: 3159
Member response

Hi,

Yes, look at;
http://cve.mitre.org/cgi-bin/cvename...=CVE-2015-8370

I posted the article to inform others that may not know anything about the problem.
 
Old 12-19-2015, 07:03 AM   #6
Habitual
LQ Veteran
 
Registered: Jan 2011
Location: Abingdon, VA
Distribution: Catalina
Posts: 9,374
Blog Entries: 37

Rep: Reputation: Disabled
Grub2, you heartless bitch.
 
Old 12-20-2015, 05:52 AM   #7
ondoho
LQ Addict
 
Registered: Dec 2013
Posts: 19,872
Blog Entries: 12

Rep: Reputation: 6053Reputation: 6053Reputation: 6053Reputation: 6053Reputation: 6053Reputation: 6053Reputation: 6053Reputation: 6053Reputation: 6053Reputation: 6053Reputation: 6053
it's mostly FUD against linux.

the grub manual itself kind of states that its inbuilt authentication system is neither very useful nor very secure:
https://www.gnu.org/software/grub/ma....html#Security

it's a grub bug and has been solved in recent version:
https://security-tracker.debian.org/.../CVE-2015-8370

also see here:
https://forums.bunsenlabs.org/viewtopic.php?id=880
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
LXer: Vulnerability in popular bootloader puts locked-down Linux computers at risk LXer Syndicated Linux News 0 12-17-2015 08:22 PM
LXer: Vulnerability in popular bootloader puts locked-down Linux computers at risk LXer Syndicated Linux News 0 12-16-2015 01:11 PM
LXer: New OpenSSL vulnerability puts encrypted communications at risk of spying LXer Syndicated Linux News 0 06-06-2014 06:40 AM
LXer: Linux Users Face Risk From Kernel Vulnerability LXer Syndicated Linux News 0 08-20-2010 02:00 AM
LXer: DNS Hole Puts E-Mail at Risk LXer Syndicated Linux News 0 04-15-2007 04:46 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - General

All times are GMT -5. The time now is 10:17 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration