Bitcoin Forum
June 21, 2024, 04:21:19 PM *
News: Voting for pizza day contest
 
   Home   Help Search Login Register More  
Pages: [1]
  Print  
Author Topic: [NEWS] Hack Into a Linux Computer by Hitting the Backspace 28 Times  (Read 506 times)
Spoetnik (OP)
Legendary
*
Offline Offline

Activity: 1540
Merit: 1011


FUD Philanthropist™


View Profile
December 23, 2015, 04:50:51 AM
 #1

http://motherboard.vice.com/read/hack-into-a-linux-computer-by-hitting-the-backspace-28-times?

Quote
If you’re trying to steal someone’s files from his or her computer, getting past the login screen can be hard, if not impossible. But thanks to a bizarre bug in several distributions of Linux, all you need is to hit the backspace key 28 times.

Two security researchers from the Cybersecurity Group at the Polytechnic University of Valencia (UPV) in Spain found that it’s possible to bypass any kind of authentication and take control of a locked-down computer that runs Linux just by hitting the backspace 28 times. The bug is in Grub2, the bootloader used to initialize “most Linux systems,” according to the researchers, who published their research on Tuesday.

If the system is vulnerable to this bug, the attacker can access what’s called the “Grub rescue shell” and gain access to the computer’s data, allowing him or her to install persistent malware, simply steal all the data, or destroy it, according to researchers Hector Marco and Ismael Ripoll.

    ”The number of backspaces hits was the only input controllable by the user to cause different manifestations of the error.”

The researchers found that hitting the backspace 28 times causes an error in the systems’ memory that launches the rescue function. The researchers found that hitting the backspace 28 times, and only 28 times, returned the value needed to trigger the error. Marco told Motherboard that they studied the code underlying the bootloader and “concluded the number of backspaces hits was the only input controllable by the user to cause different manifestations of the error.”

Other than a weird and somewhat funny bug, this is also something that just should not happen, according to security experts.

”It is irresponsible for grub to lack decades-old exploit mitigations like stack cookies that could have addressed this issue,” Dan Guido, the founder of security firm Trail of Bits, told Motherboard.

The researchers speculate that such a bug could be used by spies to install malware on a target’s computer to steal his or her files. The spies could install persistent malware on the machine that survives reboots and even new installs.

Luckily, the two also made a patch that prevents the error that triggers the bug from occurring. So if you’re worried your Linux system might be vulnerable, you might want to apply this emergency patch. Ubuntu, Red Hat, and Debian all have released fixes too.

While the impact of this bug is limited, given that an attacker needs physical access to the machine, it’s a good reminder that computer systems are sometimes vulnerable to silly bugs like this.

FUD first & ask questions later™
Maskedman
Sr. Member
****
Offline Offline

Activity: 244
Merit: 250


View Profile
December 23, 2015, 04:52:20 AM
 #2

Does this actually work? Have you tried it?
Crash21
Newbie
*
Offline Offline

Activity: 154
Merit: 0


View Profile
December 23, 2015, 05:22:49 AM
 #3

Does this actually work? Have you tried it?
Also interested in it.
Windpower
Hero Member
*****
Offline Offline

Activity: 532
Merit: 501



View Profile
December 23, 2015, 05:31:49 AM
 #4

How is this even possible.

The most secure computer(so called) can be hacked by pressing backspace.

xD
Spoetnik (OP)
Legendary
*
Offline Offline

Activity: 1540
Merit: 1011


FUD Philanthropist™


View Profile
December 23, 2015, 06:00:16 AM
 #5

How is this even possible.

The most secure computer(so called) can be hacked by pressing backspace.

xD

exploits a bug in the often used popular Grub bootloader.

FUD first & ask questions later™
BADecker
Legendary
*
Offline Offline

Activity: 3822
Merit: 1373


View Profile
December 23, 2015, 06:15:19 AM
 #6

Wouldn't it be a lot easier to start-up from a USB MAC or Windows program, and simply examine the files? The only protection you have for sensitive files is the old Truecrypt, VeraCrypt, or some kind of PGP file protection.

Smiley

Cure your cancer at home. Ivermectin, fenbendazole, methylene blue, and hydroxychloroquine (HCQ) are chief among parasite drugs. Find out that all disease is based in parasites or pollution, and what you can easily do about it - https://www.huldaclark.com/, https://thedrardisshow.com/, https://thehighwire.com/.
Spoetnik (OP)
Legendary
*
Offline Offline

Activity: 1540
Merit: 1011


FUD Philanthropist™


View Profile
January 04, 2016, 05:52:26 PM
 #7

Wouldn't it be a lot easier to start-up from a USB MAC or Windows program, and simply examine the files? The only protection you have for sensitive files is the old Truecrypt, VeraCrypt, or some kind of PGP file protection.

Smiley

Easier ? No.

FUD first & ask questions later™
Pages: [1]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!