Linux Vulnerability Lets Anyone Log in by Tapping Backspace 28 Times

Advertisement
By Manish Singh | Updated: 21 December 2015 14:11 IST

A newly discovered vulnerability makes it incredibly easy to break into a large pool of Linux-based computers. A security hole found in Grub2, a widely-used bootloader in many Linux distributions including Ubuntu and Red Hat, allows a user to login to a computer by pressing the backspace key 28 times. Various Linux distributions have released a patch for the vulnerability.

Hector Marco and Ismael Ripoll, two security researchers from the Cyber-security Group at the Polytechnic University of Valencia (UPV), have found that it is possible to bypass any kind of authentication on a Linux system by hitting the backspace key 28 times. Once users log in, they can take complete control of the computer. The researchers said Grub2 is the "bootloader used by most Linux systems including some embedded systems. This results in an incalculable number of affected devices," the researchers wrote in a blog post.

Advertisement

As per the researchers, the vulnerability can be exploited to obtain something called a "Grub rescue shell" which can, in turn, allow a user to load a customised kernel, and run arbitrary programs. The attacker could also destroy any data including the Grub itself.

The security hole stems from a simple integer underflow fault that was introduced to Grub2 in late 2009. Linux users can assess whether their computer is vulnerable by entering the backspace 28 times. Ubuntu, Red Hat, and Debian all have released patches to fix the vulnerability, though if your choice of Linux is still not covered, Marco and Ripoll have made available an emergency patch.

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement

Related Stories

Popular Mobile Brands
  1. Motorola Edge 70 Pro Arrives With a 6,500mAh Battery at This Price in India
  2. Elden Ring Movie Film Adaptation Release Date, Full Cast Revealed
  1. NASA’s Curiosity Rover Finds Crater Filled With Sand, Alters Drilling Plans
  2. Control Ultimate Edition Arrives on iPhone and iPad With Touch Controls, Universal Purchase
  3. Asus ExpertBook Ultra With Intel Core Ultra X7 Series 3 CPU Launched in India Alongside ExpertBook P3, ExpertBook P5 Series
  4. Boat Aavante Prime X Soundbar Launched in India With Dolby Atmos, Wireless Satellite Speakers: Price, Features
  5. Qualcomm CEO Reportedly Visits Samsung Foundry in Korea to Discuss Producing 2nm Chips
  6. Coinbase Announces USDC-INR Trading Services for Users in India
  7. Redmi K Pad 2 Launched With 8.8-Inch 3K Display, Dimensity 9500 Chip: Price, Specifications
  8. Suyodhana OTT Release Date: When and Where to Watch This Telugu Mystry Thriller Online?
  9. OnePlus Watch 4 Launch Appears Imminent as Listing Confirms Snapdragon W5 Chip, OxygenOS Watch 8
  10. Sennheiser CX 80U, Sennheiser HD 400U With USB Type-C Connectivity Launched in India: Price, Features
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.