Re: Data security Was: SSH



On Thu, 2005-12-08 at 21:09 -0500, Leonard Isham wrote:
> On 12/8/05, Danny Terweij - Net Tuning | Net <d.terweij@xxxxxxxxxxxxx> wrote:
> >
> > From: "Terry Polzin" <fox3ec208@xxxxxxxxxxxxxxxx>
> >
> >
> > >I'd boot into rescue mode and vi the /etc/shadow file and remove the
> > passwords
> > >then reboot normal. The accounts will then have no password and then you
> > >could generate your own passwords.
> >
> >
> > Eeks!. I thought linux was better then windows with passwords security.
> >
> > So when your laptop/server/pc is stolen all they have to do is this and gets
> > full access as root with no pass?
> >
> > Next question, how to prevent this ?
> >
>
> Welcome. Now tou know why physical security is a must. Encryption
> with a strong passphrase. There is support for encrytped loopbacks.
> THe options and details are quite lengthy. Google and you will find
> articles and how-to's onthe subject. Also google PGP and GPG
> (http://www.gnupg.org/) for more information.
----
there is the ability to require a boot password for grub but generally,
if you can boot from a cd, you can still access files.

Then of course, you can boot into runlevel 1 instead of 'rescue mode'
and change passwords

Then of course, you probably shouldn't edit /etc/shadow directly but
rather simply issue 'passwd USER_NAME' even in runlevel 1 mode to reset
passwords.

Craig

--
fedora-list mailing list
fedora-list@xxxxxxxxxx
To unsubscribe: https://www.redhat.com/mailman/listinfo/fedora-list



Relevant Pages

  • Mobile Device Security, Was: Re: Dell BIOS DoS
    ... get rid of vendor master passwords and such. ... On Apple machines the boot ROM contains a graphical ... where is the real point of attack? ... Imagine someone stealing your laptop which is ssecured with some sort of ...
    (Bugtraq)
  • Re: How do I make w2k secure for logon?
    ... > That's two passwords just to boot the computer. ... > can do with a boot diskette, especially if you soup it up a little. ... > But nothing will protect it from a serious cracker, ...
    (microsoft.public.win2000.general)
  • Re: How do I make w2k secure for logon?
    ... That's two passwords just to boot the computer. ... While you are in the BIOS, set it to only allow boot from the hard drive. ... The final touch is a locked, bolted-down safe in a restricted access room ...
    (microsoft.public.win2000.general)
  • Re: Transfering files from pw protected user account to new drive - help!
    ... window's passwords. ... Windows sees this slave drive as the G: ... this is to explain why I can't just boot off the old ... successfully got into the GoBack recovery system and disabled GoBack, ...
    (microsoft.public.windowsxp.help_and_support)
  • RE: How to recover root password
    ... I haven't tried it on any redhat machines yet, ... amounts to a "single-user" mode off of a floppy or cdrom. ... written to recover forgotten windows passwords. ... and boot off of it. ...
    (RedHat)