{"id":41110,"date":"2020-02-05T21:30:57","date_gmt":"2020-02-05T18:30:57","guid":{"rendered":"https:\/\/prohoster.info\/blog\/blog_prohoster\/metody-otklyucheniya-zashhity-lockdown-v-ubuntu-dlya-udalyonnogo-obhoda-uefi-secure-boot"},"modified":"2020-02-05T21:30:57","modified_gmt":"2020-02-05T18:30:57","slug":"metody-otklyucheniya-zashhity-lockdown-v-ubuntu-dlya-udalyonnogo-obhoda-uefi-secure-boot","status":"publish","type":"post","link":"https:\/\/prohoster.info\/fr\/blog\/metody-otklyucheniya-zashhity-lockdown-v-ubuntu-dlya-udalyonnogo-obhoda-uefi-secure-boot","title":{"rendered":"M\u00e9thodes de d\u00e9sactivation de la protection Lockdown dans Ubuntu pour contourner UEFI Secure Boot \u00e0 distance","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>Andrey Konovalov de la soci\u00e9t\u00e9 Google <noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/xairy\/unlockdown\">a publi\u00e9<\/a><\/noindex> m\u00e9thode de d\u00e9sactivation \u00e0 distance de la protection  <noindex><a rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=51591\">Verrouillage<\/a><\/noindex>, propos\u00e9e dans le paquet avec le noyau Linux, livr\u00e9 avec Ubuntu (modes th\u00e9oriquement propos\u00e9s <noindex><a rel=\"nofollow\" href=\"https:\/\/bugzilla.redhat.com\/show_bug.cgi?id=1599197\">doivent<\/a><\/noindex> fonctionner avec le noyau Fedora et d'autres distributions, mais ils n'ont pas \u00e9t\u00e9 test\u00e9s). <\/p>\n<p>Le m\u00e9canisme Lockdown limite l'acc\u00e8s de l'utilisateur root au noyau et bloque les chemins de contournement du d\u00e9marrage s\u00e9curis\u00e9 UEFI. Par exemple, en mode lockdown, l'acc\u00e8s \u00e0 \/dev\/mem, \/dev\/kmem, \/dev\/port, \/proc\/kcore, debugfs, le mode de d\u00e9bogage kprobes, mmiotrace, tracefs, BPF, PCMCIA CIS (Card Information Structure), certaines interfaces ACPI et les registres MSR CPU, les appels kexec_file et kexec_load sont bloqu\u00e9s, la possibilit\u00e9 de passer en mode veille est interdite, l'utilisation de DMA pour les p\u00e9riph\u00e9riques PCI est limit\u00e9e, l'importation du code ACPI \u00e0 partir de variables EFI est interdite, et les manipulations des ports d'entr\u00e9e\/sortie, y compris la modification du num\u00e9ro d'interruption et du port d'entr\u00e9e\/sortie pour le port s\u00e9rie, sont interdites.<\/p>\n<p>Le m\u00e9canisme Lockdown a r\u00e9cemment \u00e9t\u00e9 ajout\u00e9 au noyau Linux <noindex><a rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=51881\">5.4<\/a><\/noindex>, mais dans les noyaux fournis dans les distributions, il est toujours mis en \u0153uvre sous forme de correctifs ou compl\u00e9t\u00e9 par des correctifs. L'une des diff\u00e9rences entre les modules fournis dans les distributions et la mise en \u0153uvre int\u00e9gr\u00e9e au noyau est la possibilit\u00e9 de d\u00e9sactiver le blocage fourni en ayant un acc\u00e8s physique au syst\u00e8me. <\/p>\n<p>Dans Ubuntu et Fedora, la combinaison de touches Alt+SysRq+X est pr\u00e9vue pour d\u00e9sactiver Lockdown. Il est entendu que la combinaison Alt+SysRq+X ne peut \u00eatre utilis\u00e9e que lors d'un acc\u00e8s physique \u00e0 l'appareil, et en cas de violation \u00e0 distance et d'acc\u00e8s root, l'attaquant ne pourra pas d\u00e9sactiver Lockdown et, par exemple, charger dans le noyau un module non sign\u00e9 avec une racine. <\/p>\n<p>Andrey Konovalov a montr\u00e9 que les m\u00e9thodes de confirmation de la pr\u00e9sence physique de l'utilisateur li\u00e9es \u00e0 l'utilisation du clavier ne sont pas efficaces. La mani\u00e8re la plus simple de d\u00e9sactiver Lockdown serait une simulation logicielle <noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/xairy\/unlockdown\/blob\/master\/00-sysrq-trigger\/run.sh\">de<\/a><\/noindex> la pression des touches Alt+SysRq+X via \/dev\/uinput, mais cette option est initialement bloqu\u00e9e. Il a \u00e9t\u00e9 possible d'identifier au moins deux autres fa\u00e7ons de substituer Alt+SysRq+X. <\/p>\n<p>La premi\u00e8re m\u00e9thode consiste \u00e0 utiliser l'interface \u00ab sysrq-trigger \u00bb \u2014 pour simuler, il suffit d'activer cette interface en \u00e9crivant \u00ab 1 \u00bb dans \/proc\/sys\/kernel\/sysrq, puis d'\u00e9crire \u00ab x \u00bb dans \/proc\/sysrq-trigger. La faille mentionn\u00e9e. <noindex><a rel=\"nofollow\" href=\"https:\/\/bugs.launchpad.net\/ubuntu\/+source\/linux\/+bug\/1851380\">a \u00e9t\u00e9 corrig\u00e9e<\/a><\/noindex> a \u00e9t\u00e9 incluse dans la mise \u00e0 jour de d\u00e9cembre du noyau Ubuntu et dans Fedora 31. Il est notable que les d\u00e9veloppeurs, comme dans le cas de \/dev\/uinput, ont initialement <noindex><a rel=\"nofollow\" href=\"https:\/\/git.launchpad.net\/~ubuntu-kernel\/ubuntu\/+source\/linux\/+git\/bionic\/commit\/?id=531c25a35b2a93e025e72e04f16b0f3620ace581\">essay\u00e9<\/a><\/noindex> bloquer cette m\u00e9thode, mais le blocage n'a pas fonctionn\u00e9 en raison de <noindex><a rel=\"nofollow\" href=\"https:\/\/lore.kernel.org\/lkml\/15833.1551974371@warthog.procyon.org.uk\/\">l'erreur<\/a><\/noindex> dans le code.<\/p>\n<p>La deuxi\u00e8me m\u00e9thode concerne l'\u00e9mulation du clavier via  <noindex><a rel=\"nofollow\" href=\"http:\/\/usbip.sourceforge.net\/\">USB\/IP<\/a><\/noindex> et l'envoi ult\u00e9rieur de la s\u00e9quence Alt+SysRq+X depuis un clavier virtuel. Dans le noyau USB\/IP fourni avec Ubuntu, USB\/IP est par d\u00e9faut activ\u00e9 (CONFIG_USBIP_VHCI_HCD=m et CONFIG_USBIP_CORE=m) et les modules usbip_core et vhci_hcd sign\u00e9s num\u00e9riquement sont fournis. Un attaquant peut <noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/xairy\/unlockdown\/blob\/master\/01-usbip\/keyboard.c\">cr\u00e9er<\/a><\/noindex> un p\u00e9riph\u00e9rique USB virtuel, <noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/xairy\/unlockdown\/blob\/master\/01-usbip\/run.sh\">en lan\u00e7ant<\/a><\/noindex> un gestionnaire r\u00e9seau sur l'interface loopback et en le connectant comme un p\u00e9riph\u00e9rique USB distant via USB\/IP. Il a \u00e9t\u00e9 rapport\u00e9 concernant cette m\u00e9thode <noindex><a rel=\"nofollow\" href=\"https:\/\/bugs.launchpad.net\/ubuntu\/+source\/linux\/+bug\/1861238\">aux d\u00e9veloppeurs d'Ubuntu, mais aucun correctif n'a encore \u00e9t\u00e9 publi\u00e9.<\/a><\/noindex> Sortie de Wine 5.1 et Wine Staging 5.1<\/p>\n<p><noindex><a rel=\"nofollow\" name=\"link\"><\/a><\/noindex><\/p>\n<p>Source : <a \ncontent=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=52286\">opennet.ru<\/a><\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u0410\u043d\u0434\u0440\u0435\u0439 \u041a\u043e\u043d\u043e\u0432\u0430\u043b\u043e\u0432 \u0438\u0437 \u043a\u043e\u043c\u043f\u0430\u043d\u0438\u0438 Google \u043e\u043f\u0443\u0431\u043b\u0438\u043a\u043e\u0432\u0430\u043b \u0441\u043f\u043e\u0441\u043e\u0431 \u0443\u0434\u0430\u043b\u0451\u043d\u043d\u043e\u0433\u043e \u043e\u0442\u043a\u043b\u044e\u0447\u0435\u043d\u0438\u044f \u0437\u0430\u0449\u0438\u0442\u044b Lockdown, \u043f\u0440\u0435\u0434\u043b\u0430\u0433\u0430\u0435\u043c\u043e\u0439 \u0432 \u043f\u0430\u043a\u0435\u0442\u0435 \u0441 \u044f\u0434\u0440\u043e\u043c Linux, \u043f\u043e\u0441\u0442\u0430\u0432\u043b\u044f\u0435\u043c\u043e\u043c \u0432 Ubuntu (\u0442\u0435\u043e\u0440\u0435\u0442\u0438\u0447\u0435\u0441\u043a\u0438 \u043f\u0440\u0435\u0434\u043b\u043e\u0436\u0435\u043d\u043d\u044b\u0435 \u043c\u0435\u0442\u043e\u0434\u044b \u0434\u043e\u043b\u0436\u043d\u044b \u0440\u0430\u0431\u043e\u0442\u0430\u0442\u044c \u0441 \u044f\u0434\u0440\u043e\u043c Fedora \u0438 \u0434\u0440\u0443\u0433\u0438\u0445 \u0434\u0438\u0441\u0442\u0440\u0438\u0431\u0443\u0442\u0438\u0432\u043e\u0432, \u043d\u043e \u043e\u043d\u0438 \u043d\u0435 \u043f\u0440\u043e\u0442\u0435\u0441\u0442\u0438\u0440\u043e\u0432\u0430\u043d\u044b). Lockdown \u043e\u0433\u0440\u0430\u043d\u0438\u0447\u0438\u0432\u0430\u0435\u0442 \u0434\u043e\u0441\u0442\u0443\u043f \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u044f root \u043a \u044f\u0434\u0440\u0443 \u0438 \u0431\u043b\u043e\u043a\u0438\u0440\u0443\u0435\u0442 \u043f\u0443\u0442\u0438 \u043e\u0431\u0445\u043e\u0434\u0430 UEFI Secure Boot. \u041d\u0430\u043f\u0440\u0438\u043c\u0435\u0440, \u0432 \u0440\u0435\u0436\u0438\u043c\u0435 lockdown \u043e\u0433\u0440\u0430\u043d\u0438\u0447\u0438\u0432\u0430\u0435\u0442\u0441\u044f \u0434\u043e\u0441\u0442\u0443\u043f [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[],"tags":[],"class_list":["post-41110","post","type-post","status-publish","format-standard","hentry"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.2.1 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u0410\u043d\u0434\u0440\u0435\u0439 \u041a\u043e\u043d\u043e\u0432\u0430\u043b\u043e\u0432 \u0438\u0437 \u043a\u043e\u043c\u043f\u0430\u043d\u0438\u0438 Google \u043e\u043f\u0443\u0431\u043b\u0438\u043a\u043e\u0432\u0430\u043b \u0441\u043f\u043e\u0441\u043e\u0431 \u0443\u0434\u0430\u043b\u0451\u043d\u043d\u043e\u0433\u043e \u043e\u0442\u043a\u043b\u044e\u0447\u0435\u043d\u0438\u044f \u0437\u0430\u0449\u0438\u0442\u044b\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/fr\/blog\/metody-otklyucheniya-zashhity-lockdown-v-ubuntu-dlya-udalyonnogo-obhoda-uefi-secure-boot\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.2.1\" \/>\n\t\t<meta property=\"og:locale\" content=\"fr_FR\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u041c\u0435\u0442\u043e\u0434\u044b \u043e\u0442\u043a\u043b\u044e\u0447\u0435\u043d\u0438\u044f \u0437\u0430\u0449\u0438\u0442\u044b Lockdown \u0432 Ubuntu \u0434\u043b\u044f \u0443\u0434\u0430\u043b\u0451\u043d\u043d\u043e\u0433\u043e \u043e\u0431\u0445\u043e\u0434\u0430 UEFI Secure Boot | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u0410\u043d\u0434\u0440\u0435\u0439 \u041a\u043e\u043d\u043e\u0432\u0430\u043b\u043e\u0432 \u0438\u0437 \u043a\u043e\u043c\u043f\u0430\u043d\u0438\u0438 Google \u043e\u043f\u0443\u0431\u043b\u0438\u043a\u043e\u0432\u0430\u043b \u0441\u043f\u043e\u0441\u043e\u0431 \u0443\u0434\u0430\u043b\u0451\u043d\u043d\u043e\u0433\u043e \u043e\u0442\u043a\u043b\u044e\u0447\u0435\u043d\u0438\u044f \u0437\u0430\u0449\u0438\u0442\u044b\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/fr\/blog\/metody-otklyucheniya-zashhity-lockdown-v-ubuntu-dlya-udalyonnogo-obhoda-uefi-secure-boot\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2020-02-05T18:30:57+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2020-02-05T18:30:57+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47 M\u00e9thodes de d\u00e9sactivation de la protection Lockdown dans Ubuntu pour contourner \u00e0 distance UEFI Secure Boot | ProHoster","description":"\ud83e\udd47 M\u00e9thodes de d\u00e9sactivation de la protection Lockdown dans Ubuntu pour contourner \u00e0 distance UEFI Secure Boot | ProHoster","canonical_url":"https:\/\/prohoster.info\/fr\/blog\/metody-otklyucheniya-zashhity-lockdown-v-ubuntu-dlya-udalyonnogo-obhoda-uefi-secure-boot","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"fr_FR","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u041c\u0435\u0442\u043e\u0434\u044b \u043e\u0442\u043a\u043b\u044e\u0447\u0435\u043d\u0438\u044f \u0437\u0430\u0449\u0438\u0442\u044b Lockdown \u0432 Ubuntu \u0434\u043b\u044f \u0443\u0434\u0430\u043b\u0451\u043d\u043d\u043e\u0433\u043e \u043e\u0431\u0445\u043e\u0434\u0430 UEFI Secure Boot | ProHoster","og:description":"\u0410\u043d\u0434\u0440\u0435\u0439 \u041a\u043e\u043d\u043e\u0432\u0430\u043b\u043e\u0432 \u0438\u0437 \u043a\u043e\u043c\u043f\u0430\u043d\u0438\u0438 Google \u043e\u043f\u0443\u0431\u043b\u0438\u043a\u043e\u0432\u0430\u043b \u0441\u043f\u043e\u0441\u043e\u0431 \u0443\u0434\u0430\u043b\u0451\u043d\u043d\u043e\u0433\u043e \u043e\u0442\u043a\u043b\u044e\u0447\u0435\u043d\u0438\u044f \u0437\u0430\u0449\u0438\u0442\u044b","og:url":"https:\/\/prohoster.info\/fr\/blog\/metody-otklyucheniya-zashhity-lockdown-v-ubuntu-dlya-udalyonnogo-obhoda-uefi-secure-boot","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2020-02-05T18:30:57+00:00","article:modified_time":"2020-02-05T18:30:57+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"41110","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":null,"schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":null,"breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2021-02-28 10:48:15","updated":"2022-09-28 13:36:48","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/posts\/41110","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/comments?post=41110"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/posts\/41110\/revisions"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/media?parent=41110"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/categories?post=41110"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/tags?post=41110"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}