[Boards: 3 / a / aco / adv / an / asp / b / biz / c / cgl / ck / cm / co / d / diy / e / fa / fit / g / gd / gif / h / hc / his / hm / hr / i / ic / int / jp / k / lgbt / lit / m / mlp / mu / n / news / o / out / p / po / pol / qa / r / r9k / s / s4s / sci / soc / sp / t / tg / toy / trash / trv / tv / u / v / vg / vp / vr / w / wg / wsg / wsr / x / y ] [Home]
4chanarchives logo
http://hmarco.org/bugs/CVE-2015-837 0-Grub2-authentication-b
Images are sometimes not shown due to bandwidth/network limitations. Refreshing the page usually helps.

You are currently reading a thread in /g/ - Technology

Thread replies: 22
Thread images: 3
File: grub_hacked-b.png (183 KB, 550x529) Image search: [Google]
grub_hacked-b.png
183 KB, 550x529
http://hmarco.org/bugs/CVE-2015-8370-Grub2-authentication-bypass.html

Nice backdoor grub
>>
File: eri funy face.jpg (58 KB, 416x417) Image search: [Google]
eri funy face.jpg
58 KB, 416x417
>GRUB

GNU shitware at its finest. Use LILO or Syslinux.
>>
I've been using this bug for years. Surprised someone else finally found it.
>>
what kind of next level autist finds this out
>>
>>51880087
I wish syslinux had better UEFI support
>>
>>51880126
probably used a fuzzer
>>
>not encrypting your hard drives
If you have access to the computer you'll have access to the drives anyway
>>
>>51880126
Someone who holds backspace for a while deleting their mistyped username and then wonders why they are in rescue shell.
>>
>>51880126
Not even that obscure of a fault. The THERAC-25 radiation therapy machine had a bug in it where if you pressed a very specific sequence of keys it would give the patient a massive dose of radiation and killed like 6 people.

>The failure only occurred when a particular nonstandard sequence of keystrokes was entered on the VT-100 terminal which controlled the PDP-11 computer: an "X" to (erroneously) select 25 MeV photon mode followed by "cursor up", "E" to (correctly) select 25 MeV Electron mode, then "Enter", all within eight seconds.[4]
>>
>>51879994
good thing i use systemd-boot
>>
this is hilarious
>>
>>51880126
The kind of autist that:
>Has c knowledge
>Has asm knowledge
>Audits the grub's source code

Or:
>>51881631

So basically, a monkey.
>>
>>51881763
>thinking that isn't backdoored by poettering
>>
>>51881981
I've backdoored poetering so it's ok
>>
>>51879994
good thing i boot from efistub directly, make entries with efibootmgr
>>
>>51882030
unmanageable when you have more than 10 boot entires
>>
File: the_wreckage_sister.png (2 MB, 1920x1080) Image search: [Google]
the_wreckage_sister.png
2 MB, 1920x1080
>>51879994
This has already been patched.
>>
>>51879994
meh.... this is hardly an issue really.... thats like calling single user mode on OSX a backdoor.

If someone has access to your box and your stuff isn't encrypted this doesn't really affect anything.
>>
>>51882069
i will take your word for it, but why do you have 10 boot entries?
>>
>>51882112
Where is the plane?
>>
>>51882169
I quadruple boot ubuntu, mint, kali, and windows 10
>>
>>51882530
that sounds like 4 entries to me.
Thread replies: 22
Thread images: 3

banner
banner
[Boards: 3 / a / aco / adv / an / asp / b / biz / c / cgl / ck / cm / co / d / diy / e / fa / fit / g / gd / gif / h / hc / his / hm / hr / i / ic / int / jp / k / lgbt / lit / m / mlp / mu / n / news / o / out / p / po / pol / qa / r / r9k / s / s4s / sci / soc / sp / t / tg / toy / trash / trv / tv / u / v / vg / vp / vr / w / wg / wsg / wsr / x / y] [Home]

All trademarks and copyrights on this page are owned by their respective parties. Images uploaded are the responsibility of the Poster. Comments are owned by the Poster.
If a post contains personal/copyrighted/illegal content you can contact me at [email protected] with that post and thread number and it will be removed as soon as possible.
DMCA Content Takedown via dmca.com
All images are hosted on imgur.com, send takedown notices to them.
This is a 4chan archive - all of the content originated from them. If you need IP information for a Poster - you need to contact them. This website shows only archived content.