Debian GNU/Linux MBR Vulnerability
BID:960
Info
Debian GNU/Linux MBR Vulnerability
| Bugtraq ID: | 960 |
| Class: | Configuration Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Feb 02 2000 12:00AM |
| Updated: | Feb 02 2000 12:00AM |
| Credit: | This vulnerability was discovered and reported by Pierre Beyssac <[email protected]> on February 2, 2000 on the Bugtraq mailing list. |
| Vulnerable: |
Debian Linux 2.2 pre potato Debian Linux 2.2 Debian Linux 2.1 Debian Linux 2.0 r5 Debian Linux 2.0 |
| Not Vulnerable: | |
Discussion
Debian GNU/Linux MBR Vulnerability
A vulnerability exists in the master boot record (MBR) installed by default with Debian GNU/Linux, versions 2.0 through 2.2 prereleases. By pressing the shift key during the initial portion of the boot sequence, before LILO has been invoked, the machine will display the string "1FA:" and wait for a keypress. Pressing F will result in the floppy being booted. This can allow someone with local access to bypass any bios or LILO boot passwords.
A vulnerability exists in the master boot record (MBR) installed by default with Debian GNU/Linux, versions 2.0 through 2.2 prereleases. By pressing the shift key during the initial portion of the boot sequence, before LILO has been invoked, the machine will display the string "1FA:" and wait for a keypress. Pressing F will result in the floppy being booted. This can allow someone with local access to bypass any bios or LILO boot passwords.
Exploit / POC
Debian GNU/Linux MBR Vulnerability
Press the SHIFT key to drop to the "1FA:" prompt.
Press the SHIFT key to drop to the "1FA:" prompt.
Solution / Fix
Debian GNU/Linux MBR Vulnerability
Solution:
A patch was made available, and published as part of the 2.2.6 Debian boot floppies.
Solution:
A patch was made available, and published as part of the 2.2.6 Debian boot floppies.
References
Debian GNU/Linux MBR Vulnerability
References:
References: