[Full-disclosure] Vulnerability in Gentoo hardened
- From: klondike <klondike@xxxxxxxxxxxx>
- Date: Tue, 24 Apr 2012 17:25:41 +0200
El 24/04/12 14:41, Григорий Братислава escribió:
Is good evening.Is good afternoon.
I is would like to warn you about is vulnerability inI is want to advise you on one failure in Gentoo Hardened at all types
Backtrack is all version.
Backtrack Linux is penetration tester is system. Is come complete withGentoo Hardened is advanced security is system. Is come complete with
tool for to make hacking for penetration tester.
hardened nucleum for to make at system is securer
In is booting Backtrack, vulnerability exist in booting for when startIn is making Gentoo Hardened, failure exist in sysadmin at when usage if
if attacker is edit grub, attacker can bypass restricted user and is
boot into admin account. E.g.:
attacker is rubber hose, attacker can override authentication and is
make admin account. Making simple program. E.g.:
1. Apply rubber hose for sysadmin
2. Ask at password and try it.
3. If error make 1.
I is will make this into video for bypassing security in Backtrack forI is will be this for video by bypassing security at Gentoo Hardened or
to post on InfoSecInstitute
to post by Youtube. I is named "Reservoir Dogs".
PD: Bad English written on purpose, please forgive me for any correct
grammar I may have used :P
PD2: Григорий seeing your historial I think the mail was a joke but
anyway, just in the improbable case it may not be:
1. Bad administration issues are not global to a distro issues.
2. Make sure a vulnerability is not a not so secure by design feature.
3. Really if you ever want to write a paper or something make sure you
get it readen by at least two or three english speaking partners for
your own sake.
Attachment:
signature.asc
Description: OpenPGP digital signature
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/
- Follow-Ups:
- Re: [Full-disclosure] Vulnerability in Gentoo hardened
- From: Milan Berger
- Re: [Full-disclosure] Vulnerability in Gentoo hardened
- References:
- [Full-disclosure] Vulnerability in Backtrack
- From: Григорий Братислава
- [Full-disclosure] Vulnerability in Backtrack
- Prev by Date: Re: [Full-disclosure] We're now paying up to $20, 000 for web vulns in our services
- Next by Date: Re: [Full-disclosure] We're now paying up to $20, 000 for web vulns in our services
- Previous by thread: Re: [Full-disclosure] Vulnerability in Backtrack
- Next by thread: Re: [Full-disclosure] Vulnerability in Gentoo hardened
- Index(es):