pen-test
[Top] [All Lists]

Re: Gain root access on linux servers with physical access

To: Patrick <flymooney@gmail.com>
Subject: Re: Gain root access on linux servers with physical access
From: Gadi Evron <ge@linuxbox.org>
Date: Sat, 16 Dec 2006 20:01:32 -0600 (CST)
Cc: pen-test@securityfocus.com, pen-test-return-1078483236@securityfocus.com
Delivered-to: sp-com-lists@consult.net
Delivered-to: pentest-list2@consult.net
Delivered-to: mailing list pen-test@securityfocus.com
Delivered-to: moderator for pen-test@securityfocus.com
In-reply-to: <45848D74.3070103@gmail.com>
List-help: <mailto:pen-test-help@securityfocus.com>
List-id: <pen-test.list-id.securityfocus.com>
List-post: <mailto:pen-test@securityfocus.com>
List-subscribe: <mailto:pen-test-subscribe@securityfocus.com>
List-unsubscribe: <mailto:pen-test-unsubscribe@securityfocus.com>
Mailing-list: contact pen-test-help@securityfocus.com; run by ezmlm
Resent-date: Sat, 16 Dec 2006 21:46:35 -0700 (MST)
Resent-from: pen-test-return-1078483238@securityfocus.com
Resent-message-id: <20061217044635.05F32236F95@outgoing3.securityfocus.com>
Resent-sender: listbounce@securityfocus.com
Sender: listbounce@securityfocus.com
On Sat, 16 Dec 2006, Patrick wrote:
> spammailme@gmail.com wrote:
> > All -
> > 
> > I was wondering ideas on how to gain control of linux boxes with physical 
> > access to them in the hosting facility. 
> > 
> > The owner has code on them yet never bothered monitoring or gaining root 
> > access and her developers are blackmailing her. She has access the the 
> > hosting facility and the servers and backup staff yet needs to regain 
> > control of the servers.
> 
>    If she has physical access, then she does not need anything else 
> (other than a competent Linux person).

As a note... today statements such as (as I used to make as well) "once
you have physical access, the game is lost" are no longer true.

I divide them today by:
1. Limited-time physical access (implies #3 below).
2. Full physical access (take the machine apart).

and, if you like;
3. Surface physical access (touch the machine, don't disturb it inside the
box or power supply).

The difference is between using a USB drive to attack the machine when you
pass it by or clean the desk, to taking it apart and mounting the hard
drive to on separate box.

Using a boot disk is somewhere in the middle, which I consider #2 above
due to power-off/boot.

        Gadi.


------------------------------------------------------------------------
This List Sponsored by: Cenzic

Need to secure your web apps?
Cenzic Hailstorm finds vulnerabilities fast.
Click the link to buy it, try it or download Hailstorm for FREE.
http://www.cenzic.com/products_services/download_hailstorm.php?camp=701600000008bOW
------------------------------------------------------------------------


<Prev in Thread] Current Thread [Next in Thread>