Use OSSIM to detect Grub2 login authentication bypassing 0Day vulnerabilities
Use OSSIM to detect Grub2 login authentication bypassing 0Day vulnerabilities
The researchers found a vulnerability in Grub2 that affected versions 1.98 (released in 2009) and 2.02 (released in 2015). Through this vulnerability, local users can bypass any form of authentication (plaintext password or hash password), allowing the user to gain control of the computer. Most linux systems use Grub2 as boot loader, including some embedded systems. As a result, countless devices will be threatened by this vulnerability. We can use OSSIM to find machines that contain this vulnerability. The vulnerability library contained in OSSIM is shown in the following figure.