5 ms·
The impact of this bug is rather limited. It only matters when an attacker has a (local, not SSH) access to the console and simultaneously does not have an acce
by piotrjurkiewicz 10y ago
The impact of this bug is rather limited. It only matters when an attacker has a (local, not SSH) access to the console and simultaneously does not have an access to the hard disk.
When you have a physical access to the hard disk, you can do the same things without exploiting this bug.
- hga 10y agoIsn't that a common setup for "lights off" servers, where you use something like IMPI to get virtual "local" access to your console? Now, you should have this sort of access seriously locked down, since hardware vendors are very bad at creating secure IMPI ports, but some people don't last time I checked, which was a few years ago. And someone compromising your system for that (e.g. the firewall in front of them, the VPN to it, or your systems you use to access it) could also get in.