Skip to main content

Linux Vulnerability Lets Anyone Log in by Tapping Backspace 28 Times

A newly discovered vulnerability makes it incredibly easy to break into a large pool of Linux-based computers. A security hole found in Grub2, a widely-used bootloader in many Linux distributions including Ubuntu and Red Hat, allows a user to login to a computer by pressing the backspace key 28 times. VariousLinux distributions have released a patch for the vulnerability.

Hector Marco and Ismael Ripoll, two security researchers from the Cyber-security Group at the Polytechnic University of Valencia (UPV), have found that it is possible to bypass any kind of authentication on a Linux system by hitting the backspace key 28 times. Once users log in, they can take complete control of the computer. The researchers said Grub2 is the "bootloader used by most Linux systems including some embedded systems. This results in an incalculable number of affected devices," the researchers wrote in a blog post.

As per the researchers, the vulnerability can be exploited to obtain something called a "Grub rescue shell" which can, in turn, allow a user to load a customised kernel, and run arbitrary programs. The attacker could also destroy any data including the Grub itself. 

The security hole stems from a simple integer underflow fault that was introduced to Grub2 in late 2009. Linux users can assess whether their computer is vulnerable by entering the backspace 28 times. Ubuntu, Red Hat, and Debian all have released patches to fix the vulnerability, though if your choice of Linux is still not covered, Marco and Ripoll have made available an emergency patch.

Popular posts from this blog

Explained: Camera Improvements in the New HTC 10

With the HTC 10, the Taiwanese company is promising to undo the past wrongs in the cameras of its previous flagship phones. The camera has long a weak point in HTC devices. At first, HTC sacrificed image resolution in the M8 and made the size of individual pixels larger to capture more light (what HTC called Ultrapixel). But the resulting 4 megapixel images were often fuzzy, especially when cropped or enlarged. To fix the issue, in its next flagship - the M9 - HTC went with smaller individual pixels in a 20-megapixel camera last year, but it still underperformed in extreme situations, such as indoors and close-ups. In the HTC 10, the company attempts to strike a balance with larger individual pixels (1.55µm), but not as large as before and a 12 megapixel sensor in its camera coupled with a ƒ/1.8 lens. HTC accepts that in the imaging performance in the M9 was not up to the kind of spec of what they really like to see in a flagship. HTC is giving a slight boost to the selfi...

Freedom 251: 30,000 Units Sold, Components for Up to 2.5 Million Will Be Imported

Ringing Bells, the makers of the Rs. 251 smartphone - the Freedom 251 - confirmed to Gadgets 360 on Tuesday that it has still only accepted payments for 30,000 units of the phone. It also added that the components for these phones will be imported, and only assembled in India, not made here. Ringing Bells stopped accepting orders on February 19, and claims to have received over 70 million registrations. The company President and Director both repeatedly stated that the price of the phone would be made possible through economies of scale, and making the phone in India to cut out import costs. Economies of scale? However, in a discussion with Gadgets 360 the company revealed that it had only sold 30,000 units of the phone on day one. The company has now confirmed that it has not sent out the payment emails to anyone else who registered - "we were working out details of cash on delivery, which we are announcing now, so we will be sending emails to the first 2.5...

10 Smartphones with Features that You Won't Find in Any Other Phone

Here’s a list of phones which are first-of-their-kind. From feature phones to smartphones, flat screen to curved, fragile to shatterproof, mobile phones have evolved over the years. Although many industry analysts would like to call the current level of innovation reaching a stagnation point, there still are some manufacturers which have been able to surprise consumers by truly packing something different in their smartphones. We have compiled a list of phones which offer first-of-its-kind features, and they are not merely concepts. 1. Motorola X force - Shatterproof display Display today is the most vulnerable yet the most neglected element in modern smartphones. But Motorola finally paid heed to the fragile screen with the launch of the the Motorola X Force – the world’s first smartphone with a shatterproof display. The phone uses the Moto ShatterShield display technology, which is said to be an integrated system consisting of five layers designed from material...