New issue
Advanced search Search tips

Issue 594976 link

Starred by 1 user

Issue metadata

Status: WontFix
Owner: ----
Closed: Mar 2016
Cc:
EstimatedDays: ----
NextAction: ----
OS: ----
Pri: ----
Type: Bug-Security



Sign in to add a comment

Security: Google I/O 2012 I5 Chromebox

Reported by ntgame...@gmail.com, Mar 15 2016

Issue description

VULNERABILITY DETAILS

Not sure if this qualifies or not but I was able to completely remove ChromeOS from the system and replace it with a custom seabios intallation and am now running Core i5 + 8gb ddr3 + I've removed the 16gb ssd and replaced it with a 256GB crucial m4 msata drive. I'm able to run ubuntu linux without issues, though Windows 7 works as well.

 Additionally as far as I can tell I should be able to run an external GPU through the system by making use of the spare mini-pcie slot using a custom made adapter though in practice this hasn't worked yet it does detect the GPU. (Tested with Geforce 750TI)

VERSION
Chrome Version: NA
Operating System: ChromeOS linux kernel 3.4 Previous (Ubuntu LTS 14.04 Current)

REPRODUCTION CASE
Put device into developer mode, run this chruboostu script I made (modified from chrubuntu script) https://github.com/austinksmith/Chruboostu once you're into Ubuntu 12.04. Once inside run this script by johnlewis, I personally used a custom build as my i5 stumpy model is the only one as far as I know that has been exploited this way. His builds officially only support the Celeron version of stumpy.  https://johnlewis.ie/flash_chromebook_rom.sh

FOR CRASHES, PLEASE INCLUDE THE FOLLOWING ADDITIONAL INFORMATION
Type of crash: NA
Crash State: NA
Client ID (if relevant): NA

 

Comment 1 by mea...@chromium.org, Mar 15 2016

Cc: rickyz@chromium.org kerrnel@chromium.org
Thanks for the report. Replacing the OS in dev mode is supported as explained in https://www.chromium.org/chromium-os/developer-information-for-chrome-os-devices/custom-firmware, and the last paragraph in that page points to slides that explain installing your own bios, but I'm not sure if there is something I'm missing here. CC'ing some folks who are more knowledgeable than me.

Comment 2 by rickyz@chromium.org, Mar 15 2016

Labels: -Restrict-View-SecurityTeam
Status: WontFix (was: Unconfirmed)
Thanks meacer@, yeah, I think this is supported functionality and not a security bug - happy hacking :-)
Project Member

Comment 3 by sheriffbot@chromium.org, Oct 1 2016

This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
Project Member

Comment 4 by sheriffbot@chromium.org, Oct 2 2016

This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
Labels: allpublic

Sign in to add a comment