Slashdot Mirror


User: pepa65

pepa65's activity in the archive.

Stories
0
Comments
6
First seen
Last seen
Profile
(view on slashdot.org)

Comments · 6

  1. I tried this on one of my systems, and indeed, it dropped me to a root busybox shell in initrd. Since my grub is not password protected, this kind of access (and worse) was already trivial on that system. But, LUKS is still encrypted.

    Nowadays grub supports what I call total encryption. (It has support for a LUKS encrypted partition, no need for a separate unencrypted /boot directory.) Now a similar vulnerability was present on one of my total-encrypted systems, but in this case it dropped me to a grub rescue environment.

    I would be interested to hear what the possibilities are for evil maid attacts in the grub rescue shell scenario, but I don't believe it's possible, because the kernel and the initrd are still encrypted.

  2. initramfs, not cryptsetup on Cryptsetup Vulnerability Grants Root Shell Access On Some Linux Systems (threatpost.com) · · Score: 1

    It has been said, but the vulnerability is not in cryptsetup, but in initramfs.

  3. Re:Hype Brick or real Brick? on Running "rm -rf /" Is Now Bricking Linux Systems (phoronix.com) · · Score: 1

    So you have a JTAG or EEPROM programmer -- would you know how to fix it if the efivars had just gotten wiped?? I would love to have access to resources and instructions on what needs to happen..!

  4. Re:Perhaps some terminal commands should be locked on Running "rm -rf /" Is Now Bricking Linux Systems (phoronix.com) · · Score: 1

    Number 4 (>/dev/sda) doesn't really do anything, as /dev/sda is a block device. On a regular file it would get truncated to length zero.

  5. Re:/bin/sh means Bourne compatibility on Flurry of Scans Hint That Bash Vulnerability Could Already Be In the Wild · · Score: 1

    THIS! Can this be modded up?? (On the other hand, systems are getting hacked, so just using bash works...)
    Also, it needs reiterating that all those Androids and routers commonly don't have any bash on board.

  6. Re:What happened to Debian? on Debian Switching Back To GNOME As the Default Desktop · · Score: 3, Insightful

    I think you got that backwards. Canonical started using systemd because Debian picked it. Also, Canonical doesn't do Gnome3 shell on their main offering, so how do you see any strongarming in this decision?