MESSAGE
DATE | 2015-12-26 |
FROM | Chris Knadle
|
SUBJECT | Re: [Hangout-NYLXS] GRUB Vulnerability
|
Elfen Magix: > I doubt this vulnerability exists though it is my opinion of it. And like > it is stated, it's a non-story. > > If a "hacker" can get physical access to the machine then it is already > vulnerable. Control-Alt-Delete and then 'F1', 'F2', 'F10', 'F12', 'Esc', > 'Delete' or what ever your systems' key combination for BIOS Access is, > change a few BIOS Entries and then Reboot. They will have full access > afterwards if they boot up from CD/DVD or Thumb Drive. Want to post this > as a vulnerability? I almost did.
It /is/ a vulnerability, because the exploit allows an attacker to bypass a built-in security feature.
Besides that, it's possible to set up full disk encryption including /boot, in which case having a password in GRUB makes a lot more sense.
Thus... it's "not news" to those not running full disk encryption.
-- Chris
-- Chris Knadle Chris.Knadle-at-coredump.us _______________________________________________ hangout mailing list hangout-at-nylxs.com http://www.nylxs.com/
|
|