February 2018
Intermediate to advanced
396 pages
9h 38m
English
This exploit was presented in the Deepsec In-depth security conference 2016 in Vienna. The talk was titled Abusing LUKS to Hack the System. During the session, the researcher showed a dangerous way to use a vulnerability in Cryptsetup to decrypt the host partition. This exploit gives you root access to the attacked machine, and the ability to do whatever with the disk. The vulnerability was caused by a mishandling of password check. Thus, when a user attempts to enter password more than three times, the system proceeds with the boot sequence normally:

Read now
Unlock full access