Go Back   Linux Forums by TotalPenguin! Get linux Help! > Linux > Linux Web Server

Linux Web Server Web Server help and support (including cpanel, whm, plesk, etc.)

Reply
 
LinkBack Thread Tools Search this Thread Display Modes
  #11 (permalink)  
Old 11-30-2008, 04:12 PM
TotalPenguin's Avatar
Administrator
 
Join Date: May 2007
Posts: 470
TotalPenguin will become famous soon enoughTotalPenguin will become famous soon enough
Default

So the only way to access it from localhost would mean that they have to hack your root, right?
__________________
Business Directory
Technology Blog
Reply With Quote
  #12 (permalink)  
Old 12-02-2008, 03:30 PM
Tor Tor is offline
Senior Member
 
Join Date: Oct 2007
Posts: 394
Tor is on a distinguished road
Default

I believe so.
Reply With Quote
  #13 (permalink)  
Old 12-02-2008, 04:53 PM
Member
 
Join Date: Dec 2008
Posts: 44
MarkA is on a distinguished road
Default

Yeah, I guess they have to! They will have to SSH or something...
Reply With Quote
  #14 (permalink)  
Old 12-04-2008, 02:37 PM
Tor Tor is offline
Senior Member
 
Join Date: Oct 2007
Posts: 394
Tor is on a distinguished road
Default

If they have access to your hardware they can boot in single user mode and not have to put a password in at all. The point here is to keep your doors locked to your servers.
Reply With Quote
  #15 (permalink)  
Old 12-04-2008, 02:48 PM
Member
 
Join Date: Dec 2008
Posts: 44
MarkA is on a distinguished road
Default

But still.. even if they had hardware access.. they can't just log into the root account.. right?
Reply With Quote

Sponsored Links
  #16 (permalink)  
Old 12-04-2008, 04:51 PM
Super Moderator
 
Join Date: Nov 2008
Posts: 71
WingedPanther is on a distinguished road
Default

If they have a live CD, they can change the root password on your system and get access.
Reply With Quote
  #17 (permalink)  
Old 12-05-2008, 01:01 PM
Jordan's Avatar
Administrator
 
Join Date: Nov 2006
Posts: 572
Jordan will become famous soon enough
Default

A live CD would give them full access like WingedPanther stated. I believe when you boot in single user mode you do not have to supply a password for root either. If a person has physical access there is nothing your virtual security can really do.
Reply With Quote
  #18 (permalink)  
Old 12-05-2008, 01:03 PM
Member
 
Join Date: Dec 2008
Posts: 44
MarkA is on a distinguished road
Default

Waw.. that's.. that's.. that makes all security null... OMG!
Reply With Quote
  #19 (permalink)  
Old 12-06-2008, 01:27 PM
Super Moderator
 
Join Date: Nov 2008
Posts: 71
WingedPanther is on a distinguished road
Default

Thus the statement that you network is only as secure as your ability to keep people out. There was an experiment not long ago where a company was using RFID chips for their building access. A white-hat outfit used a scanner in front of the building to secretly copy the RFID code and gained access to the building. So much for "security". If you have access to the server, you can take it apart, put drives in other computers, etc. If I have your computer, I have your data.
Reply With Quote
  #20 (permalink)  
Old 12-10-2008, 01:07 PM
Tor Tor is offline
Senior Member
 
Join Date: Oct 2007
Posts: 394
Tor is on a distinguished road
Default

The should use the key/code combination. For instance, they have the RFID chips and then they would need something else like a code only known to them. Or some form of ID.
Reply With Quote

Sponsored Links
Reply

Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Similar Threads
Thread Thread Starter Forum Replies Last Post
sudo: must be setuid root mop Linux General 2 08-19-2008 09:02 PM
Remove User Password Hektor Linux Security 8 06-24-2008 02:12 PM
sudoers without password Tor Linux General 2 04-07-2008 10:46 PM
Enforce Password Change Wanch Linux Security 6 03-23-2008 03:52 AM
MySQL Root Password Prog Linux Applications 1 10-08-2007 08:38 PM


All times are GMT. The time now is 01:00 AM.


Powered by vBulletin® Version 3.7.0
Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.