URL: https://linuxfr.org/users/octane/journaux/faille-de-s%C3%A9curit%C3%A9-dans-grub Title: faille de sécurité dans GRUB Authors: octane Date: 2009年12月14日T11:57:52+01:00 Tags: grub et cybersécurité Score: 9 Bonjour, une petite faille de sécurité ''amusante'' [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=555195](http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=555195) GRUB accepts user input as valid password as long as user enters some first characters of password correctly. I.e. if /boot/grub/grub.cfg reads: set superusers="user1" password user1 password1 Then user can enter "p", "pa", "pas" etc, and GRUB will 'eat it' as correct password. Considering that this 'feature' effectively lowers password length to 1 (one), I've set severity of this bug to 'important'. Feel free to add 'security' tag, if appropriate. --> Moi, je le flaggerai bien comme 'important' et comme 'security' tag! Donc, mettez vous à jour, un caractère comme force d'un mot de passe, c'est tout de même peu :-)

AltStyle によって変換されたページ (->オリジナル) /