Are you sure? It looked like rootkits/bootkits are still pretty rampant?
Are you sure? It looked like rootkits/bootkits are still pretty rampant?
1. Look at this bug! lolz,pwnd
2. Script kiddie tools made around it and lots of variants are popular
3. Security improves as prevention tools get better
4. 0day experts look in other systems. (aka goto 1 with a different subsystem argument).
5. Eventually, as techniques in all subsystems improve, the original area of exploration is again the lowest hanging fruit, with a slightly different guise.
For example - SQL injection is just a variant of the old pipe injection attack (also, pipe injection is coming back a bit, because newer programmers haven't seen it, and older programmers have forgotten about it).
Another example you're starting to see more of again: IP stack attacks - as ip is being offloaded into the NIC you're starting to see a revival of "lets see what we can do to the ip stack" but this time it's in the card itself. (Actually there is some really cool stuff going on here...)
So yeah, boot time attacks are pretty common and in these days, but not necessarily in the main boot path, but in cards with firmware, especially those that have DMA.
Additionally with tools like metasploit, you can keep around a huge toolkit of root-kits and so on, so if a system is vulnerable to known boot-time exploits, you can use them even if you'd forgotten them.
|adduser ...
or change the password, or so on to get a root shell or account.This has actually come back into style in certain places again, because so many devices are just linux boxes with busybox utils on constrained systems (think home routers for example a lot of those just display the output from various linux commands in their firewall stuff). But programmers don't always think about "what if someone is going to try and do pipe on this..." and you end up with a pipe injection.
It also can be used for privilege escalation if you have a lot of custom setuid stuff available for your sysadmins and someone manages to get a local account. (unfortunately more common than one would hope).
It's common sense, really.
* run the OS from (known good) media mounted read-only (in the olden days, some websites ran off Knoppix CD's and rebooted often :)
* (Red Hat): rpm -Va to verify the package database, binaries, config files etc. (after verifying the original package database hasn't changed, by checksumming / diffing with an offline copy)
* iptables rules which drop (and log) all traffic on all interfaces (then selectively add minimalist rules)
That sounds horrific for performance.
Non executable data (the majority of data served by webservers) can still reside on magnetic media or on a NAS.