HomeSecurityTake control of a Linux system in 70 seconds

Take control of a Linux system in 70 seconds

Attackers need just over a minute to gain access to Linux systems by holding down the Enter key for exactly 70 seconds. This “hack” grants them a root initramfs shell.

The simple exploit exists due to a bug in the Linux Unified Key Setup (LUKS) used by popular Linux distributions.
linux-bug

It should be noted that with shell access, an attacker could decrypt systems. The attack also works on Linux virtual machines in the Cloud.

Debian and Fedora are two distributions that have been confirmed to be vulnerable to the problem.

The problem was discovered by Hector Marco, a lecturer at the University West of Scotland, along with assistant professor Ismael Ripoll from the Polytechnic University of Valencia. The researchers say the problem does not require any special system configuration, stating:

This vulnerability allows [the hacker] to obtain a root initramfs shell on affected systems. The vulnerability is very reliable, because it does not depend on specific systems or configurations.

Attackers can copy, modify or destroy the hard drive, as well as create a network to extract data. The vulnerability is particularly serious in environments such as libraries, ATMs, airport machines, laboratories, etc., where the entire boot process is protected by the BIOS and GRUB password and only a keyboard and/or mouse are available.

The exploit has been patched according to Marco and Ripoll.

https://hmarco.org/bugs/CVE-2016-4484/CVE-2016-4484_cryptsetup_initrd_shell.html

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS