Linode Forum
Linode Community Forums
 FAQFAQ    SearchSearch    MembersMembers      Register Register 
 LoginLogin [ Anonymous ] 
Post new topic  Reply to topic
Author Message
PostPosted: Tue Jan 01, 2008 11:34 am 
Offline
Junior Member

Joined: Tue Jan 01, 2008 11:31 am
Posts: 38
hy,
i disabled root login with ssh. is there a way to limit lish login too?
thanks


Top
   
 Post subject:
PostPosted: Tue Jan 01, 2008 12:03 pm 
Offline
Senior Member

Joined: Fri Dec 07, 2007 1:37 am
Posts: 385
Location: NC, USA
Maybe remove tty0 from /etc/securetty?
I think this should prevent root logins, but if they have already managed to login to lish you are probably completely pwned anyway.


Top
   
 Post subject:
PostPosted: Tue Jan 01, 2008 12:23 pm 
Offline
Junior Member

Joined: Tue Jan 01, 2008 11:31 am
Posts: 38
removing tty0 means every user except root can log in, but every user can do a su - and become root, right? i have vc/0 - 11 and tty0 - 11 in the file, whats that? i thought vc is an alias for tty?

i want to do it because this way one has to break two passwords to gain root access.


Top
   
 Post subject:
PostPosted: Tue Jan 01, 2008 12:38 pm 
Offline
Senior Member

Joined: Fri Dec 07, 2007 1:37 am
Posts: 385
Location: NC, USA
cattani wrote:
removing tty0 means every user except root can log in, but every user can do a su - and become root, right? this way one has to break two passwords to gain root access.

Yes, anyone but root could login through the console, and then they could su from there if they are normally allowed to. Really this would require three passwords - lish, regular user, root.
However if they can login to lish, that means they can access your account and do pretty much anything they want, for example installing and booting into a new disk image, or canceling your account. Probably no limit to the BadThings they could do with that one password.


Top
   
 Post subject:
PostPosted: Tue Jan 01, 2008 12:45 pm 
Offline
Junior Member

Joined: Tue Jan 01, 2008 11:31 am
Posts: 38
hmm, so i need to disable lish, any idea how to? thanks!


Top
   
 Post subject:
PostPosted: Tue Jan 01, 2008 3:35 pm 
Offline
Senior Member

Joined: Tue Apr 27, 2004 5:10 pm
Posts: 212
cattani wrote:
hmm, so i need to disable lish, any idea how to? thanks!

If you do this, how would you plan on gaining access to your linode if, say, networking wasn't working for some reason, or if sshd broke?

Your best solution is to do as suggested, edit /etc/securetty and use very strong passwords.


Top
   
 Post subject:
PostPosted: Tue Jan 01, 2008 3:59 pm 
Offline
Senior Member
User avatar

Joined: Tue Aug 17, 2004 11:37 pm
Posts: 262
Website: http://www.our-lan.com
WLM: nf@our-lan.com
Location: Brisbane, Australia
If they know your lish password, they can log into the members section of linode, and say reboot into finnix and change ur passwords/security options reboot, and then have full access to your stuff there. so.. Its probably not worth thinking about disabling lish. Just make sure ur password for linode.com is strong

_________________
ServerAdmin - www.our-lan.com
"Diplomacy is the art of saying nice doggy whilst looking for a really big stick"
"In my experiece, any attempt to make any system idiot proof will only challenge God to make a better idiot"


Top
   
Display posts from previous:  Sort by  
Post new topic  Reply to topic


Who is online

Users browsing this forum: No registered users and 1 guest


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum

Search for:
Jump to:  
RSS

Powered by phpBB® Forum Software © phpBB Group