MESSAGE
DATE | 2015-12-29 |
FROM | Elfen Magix
|
SUBJECT | Re: [Hangout-NYLXS] GRUB Vulnerability
|
I would like to see you break into a server through Grub's Boot options by a network connected machine. THAT is not going to happen.
I want to see demonstrated that you can have the server turned off, you on the networked machine, turn on the server and you connect to the server when GRUB kicks in, and then you break into it through GRUB with 28 backspace keystrokes on your machine. THAT is not going to happen.
You need to have physical access to the machine to do this. That makes it trivial in trying to get in when you have no keyboard access to the machine physically. So again, when you deal with the physical security of the machine and no one can have access to it - WHERE'S THE VULNERABILITY?!!
Once GRUB loads up the OS in question (Linux), then there are other directions to take to break in. But not during the GRUB Process through a network connection.
"Security is a state of mind. What does it say if your mind is not secure?" (c) 1981-FG.
--------------------------------------------
On Tue, 12/29/15, Chris Knadle wrote:
Subject: Re: [Hangout-NYLXS] GRUB Vulnerability
To: hangout-at-nylxs.com
Date: Tuesday, December 29, 2015, 2:43 AM
Elfen Magix:
[...
> So... GRUB does not
give you network access at boot time so you can't get
> in through a network.
ls /boot/grub/i386-pc/
[...]
net.mod
pxe.mod
serial.mod
tftp.mod
-- Chris
--
Chris Knadle
Chris.Knadle-at-coredump.us
_______________________________________________
hangout mailing list
hangout-at-nylxs.com
http://www.nylxs.com/
_______________________________________________
hangout mailing list
hangout-at-nylxs.com
http://www.nylxs.com/
|
|