由买买提看人间百态

boards

本页内容为未名空间相应帖子的节选和存档,一周内的贴子最多显示50字,超过一周显示500字 访问原贴
JobHunting版 - 说linux安全就是个大笑话 (转载)
相关主题
LIVE: Wikileaks Julian Assange Press Conference 3/23/17 (奥巴马要开始整H1B workers了 (转载)
一般社交网站的"friend"是怎么存储的呢?大牛们说说Fireeye的技术怎么样?
求bless 明天通知结果 有offer,发光包子建议马工们有机会多搞信息安全、安全开发方面的东西
DC地区全球性大公司cyber security researcher机会内推product manager (负责data/ML product) (转载)
airbnb 主要用的什么技术? (转载)烙印大把捞钱的机会又来了 (转载)
For real? Gmail blocked in China (转载)招聘:Vehicle Cybersecurity Advanced Development Engineer
鸠占鹊巢新闻:HACKABLE车,MASTERCARD网络安全请问码母路在何方
从国内猛搞透明计算来看:码工好日子没有5年了 (转载)Cisco AI 组招data scientist--湾区
相关话题的讨论汇总
话题: linux话题: security话题: backspace话题: hitting话题: system
进入JobHunting版参与讨论
1 (共1页)
I*******g
发帖数: 7600
1
【 以下文字转载自 Military 讨论区 】
发信人: mitbbs2715 (好吃不懒做), 信区: Military
标 题: 说linux安全就是个大笑话
发信站: BBS 未名空间站 (Thu Dec 17 22:30:48 2015, 美东)
You Can Break Into a Linux System by Pressing Backspace 28
http://lifehacker.com/you-can-break-into-a-linux-system-by-pres
Patrick Allan
Yesterday 1:30pmFiled to: SECURITY
Hitting a key over and over again actually works for once. Two security
researchers in Spain recently uncovered a strange bug that will let you into
most Linux machines just by hitting the backspace key 28 times. Here’s how
to fix it and keep your data protected.
The researchers, Hector Marco and Ismael Ripoll from the Cybersecurity Group
at Polytechnic University of Valencia, found that it’s possible to bypass
all security of a locked-down Linux machine by exploiting a bug in the Grub2
bootloader. Essentially, hitting backspace 28 times when the machine asks
for your username accesses the “Grub rescue shell,” and once there, you
can access the computer’s data or install malware. Fortunately, Marco and
Ripoll have made an emergency patch to fix the Grub2 vulnerability. Ubuntu,
Red Hat, and Debian have all issued patches to fix it as well.
Linux is often thought of as a super secure operating system, but this is a
good reminder to take physical security just as seriously as network
security (if not more). Take extra care when your machine is around people
you don’t know, especially if your system has sensitive data on it.
r**********g
发帖数: 22734
2
都可以看到grub,而且磁盘还没加密,那还不如直接把硬盘拔下来好了
f*******t
发帖数: 7549
3
首先要物理接触到机器,这个bug有点蛋疼但至少没那么可怕
m*f
发帖数: 3078
4
可以物理接触的话,直接single user mode进去了,密码都不用
f*******l
发帖数: 964
5
grub 可以设密码,防止随便进入 single user mode。 这个文章提到的 bug 就是关于
突破 grub 的密码。

【在 m*f 的大作中提到】
: 可以物理接触的话,直接single user mode进去了,密码都不用
1 (共1页)
进入JobHunting版参与讨论
相关主题
Cisco AI 组招data scientist--湾区airbnb 主要用的什么技术? (转载)
纽约AI Cybersecurity方向的startup招SDEFor real? Gmail blocked in China (转载)
跑到纽约来找工作,心里不好受!鸠占鹊巢新闻:HACKABLE车,MASTERCARD网络安全
Herguan 大学被取消招收国际学生,请问湾区还有哪家能办CPT啊从国内猛搞透明计算来看:码工好日子没有5年了 (转载)
LIVE: Wikileaks Julian Assange Press Conference 3/23/17 (奥巴马要开始整H1B workers了 (转载)
一般社交网站的"friend"是怎么存储的呢?大牛们说说Fireeye的技术怎么样?
求bless 明天通知结果 有offer,发光包子建议马工们有机会多搞信息安全、安全开发方面的东西
DC地区全球性大公司cyber security researcher机会内推product manager (负责data/ML product) (转载)
相关话题的讨论汇总
话题: linux话题: security话题: backspace话题: hitting话题: system