Re: [Full-disclosure] Vulnerability in Backtrack



I have a more critical vulnerability: "root" default password is "toor"

¬¬


2012/4/24 Григорий Братислава <musntlive@xxxxxxxxx>

Is good evening. I is would like to warn you about is vulnerability in
Backtrack is all version.

Backtrack Linux is penetration tester is system. Is come complete with
tool for to make hacking for penetration tester.

In is booting Backtrack, vulnerability exist in booting for when start
if attacker is edit grub, attacker can bypass restricted user and is
boot into admin account. E.g.:

grub edit > kernel /boom/vmlinuz-2.3.11.7 root=/dev/sda1 ro Single
[ENTER]
grub edit > b
# mount -t proc proc /proc
# mount -o remount,rw /
# passwd
[ENTER IS ANYTHING YOU WANT]
# sync
# reboot

I is will make this into video for bypassing security in Backtrack for
to post on InfoSecInstitute

--

`Wherever I is go - there am I routed`

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/

Relevant Pages

  • Re: Jump ends nowhere?!
    ... 001, backtrack that a bit... ... I was booting your supplied CD in the ... I rigged cdromboot.asm with the test code and got it to work. ... I would recommend revamping your bootable cd image. ...
    (alt.lang.asm)
  • Re: [Full-disclosure] Vulnerability in Backtrack
    ... *sigh* vulnerability reports like this make me sad. ... Backtrack Linux is penetration tester is system. ... Hosted and sponsored by Secunia - http://secunia.com/ ...
    (Full-Disclosure)
  • Re: [Full-disclosure] Vulnerability in Backtrack
    ... Backtrack Linux is penetration tester is system. ... Charter: http://lists.grok.org.uk/full-disclosure-charter.html ... Hosted and sponsored by Secunia - http://secunia.com/ ...
    (Full-Disclosure)
  • Re: [Full-disclosure] Vulnerability in Backtrack
    ... Backtrack Linux is penetration tester is system. ... Full-Disclosure - We believe in it. ... Charter: http://lists.grok.org.uk/full-disclosure-charter.html ... Hosted and sponsored by Secunia - http://secunia.com/ ...
    (Full-Disclosure)
  • Re: [Full-disclosure] =?windows-1252?q?Win_Your_Copy_of_=93BackTrack_?= =?windows-1252?q
    ... BackTrack - beautiful & powerful security distribution! ... Charter: http://lists.grok.org.uk/full-disclosure-charter.html ... Hosted and sponsored by Secunia - http://secunia.com/ ...
    (Full-Disclosure)