Press 28 times Backspace to Hack a Linux Computer

rofl cake

Well-Known Member
May 25, 2015
204
451
108
This effect's systems with older version of Grub2 this Link covers a more in depth on How and Why grub2 is exploitable. This link shows you how to fix that exploit.

Grub2 Authentication Bypass 0-Day:
Versions from 1.98 (December, 2009) to 2.02 (December, 2015) are affected.
The Exploit (PoC)
Exploiting the integer underflow can be used to cause an Off-by-two or an Out of bounds overwrite memory errors. The former error, overwrites up to two bytes right under the username buffer (local variable called login at function grub_auth_check_authentication()), but this area does not contain any usable information to build an attack; actually, it is padding.
bomba.png
 
Last edited:
Top