Re: Linux login security approaches

Agus Budy Wuysang (supes-1@usa.net)
Thu, 10 Dec 1998 09:07:04 +0700


Wesley Morgan wrote:
>
> On Tue, 8 Dec 1998, Neil Conway wrote:
>
> > Jeez, wrong on both counts. No-one needs to replace /bin/login, simply
> > print a message to the screen saying "Linux blah \n login:" and then
> > wait for someone to take the bait.
> >
> > Secondly, NT's C-A-D requirement DOES prevent this, and thus DOES add
> > security, AND to make things better, I don't see how it makes life any
> > harder for users - it's just some keys you press to get a login screen.
>
> This whole argument is stupid... If you have access to the console then
> chances are you don't need the root password to get root. Bring out your
> handy floppy disk and manually edit /etc/shadow or whatever you want. The
> attack couldn't be done remotely by any means. If you are Joe

Why floppy?

LILO: linux init=/bin/bash

will do it faster :)

> Administrator and dumb enough to let someone log onto the console who
> might run a program like that, you deserve to get hacked wide open. I'm no
> expert on the subject, but wouldn't it be nearly impossible to completely
> disguise the fact that it wasn't really a login running on a getty?

No, you disguise the *getty output screen, to appear just like
the real one, save the whatever user typed in, call/exec the real getty
later on...

> Regardless, I seriously doubt any OS is so secure you can allow open
> access to the console and not worry about it (of course you can always
> physically secure the actual case but lets not argue about this forever).

-- 
+---| Netscape Communicator 4.x |---| Powered by Linux 2.1.x |---+
|/v\ Agus Budy Wuysang                   MIS Department          |
| |  Phone:  +62-21-344-1316 ext 317     GSM: +62-816-1972-051   |
+--------| http://www.rad.net.id/users/personal/s/supes |--------+
-----BEGIN GEEK CODE BLOCK-----
Version: 3.1
GCS/IT dx s: a- C+++ UL++++$ P- L+++(++++) E--- W++ N+++ o? K? w-- O-
M- V-- PS+ PE Y-- PGP t+@ 5 X+ R- tv- b+ DI? D++(+) G e++ h* r+ y++
------END GEEK CODE BLOCK------

- To unsubscribe from this list: send the line "unsubscribe linux-kernel" in the body of a message to majordomo@vger.rutgers.edu Please read the FAQ at http://www.tux.org/lkml/