Re: Renaming root account

From: Bigby Findrake (bigby_at_ephemeron.org)
Date: 03/03/05

  • Next message: Ed Stover: "Re: Renaming root account"
    Date: Thu, 3 Mar 2005 00:16:18 -0800 (PST)
    To: Craig Edwards <brain@winbot.co.uk>
    
    

    There may be others, but here are 2...

    1. It's not a *good* idea because it's security through obscurity. It's
    not a bad idea on that account, but you should realize the limitations of
    security through obscurity when using that tactic.

    2. It's a *bad* idea because you don't know what things *might* break down
    the road, even if you did manage to either verify that nothing would break
    currently if you made the change or fixed everything that would break
    currently if you made the change.

    Also, as you suggest in your question, I believe that most binary
    executables use "uid 0" vs "root", so changing the name of the account
    there might be of limited use.

    Additionally, with many remote attack types (eg. remote buffer overflows),
    the attacker does not need to know what access he is trying to get (eg.
    root or non-root), only what service her/his attack will use as a vector.
    For example, a remote attacker may not know that sendmail is running as
    the user "root" or "fakeroot," but neither does the attacker need to know
    what user sendmail is running as *if s/he is successfully able to execute
    her/his code* - s/he has gained some sort of access, privileged or
    otherwise.

    On Thu, 3 Mar 2005, Craig Edwards wrote:

    > Hi everyone,
    >
    > One quick question: Is it safe and/or sensible to rename the root
    > account, so that the only uid 0 user on a system is something different
    > to root? I can see how this would be effective against external
    > attackers who have no knowledge of the internals of the system as they
    > would spend pointless hours trying to crack a user which doesnt exist,
    > however to internal users they could always just cat /etc/passwd and see
    > that root has been renamed. So firstly, is this possible, and security
    > wise is it of any real use? Can anyone think of any apps it would break
    > that assume that the uid 0 user is called root and don't just address
    > the user by its uid?
    >
    > Thanks,
    > Craig Edwards
    >
    > --
    > WinBot IRC client developer: http://www.winbot.co.uk
    > ChatSpike - The users network: http://www.chatspike.net
    > InspIRCd - Modular IRC server: http://www.inspircd.org
    > Online RPG Developer: http://www.ssod.org
    > --Signature by unknown keyid: 0x1962FC10
    >

    /-------------------------------------------------------------------------/
    "It was half way to Rivendell when the drugs began to take hold"
      --Hunter S Tolkien "Fear and Loathing in Barad Dur"

                        finger://bigby@ephemeron.org
                        http://www.ephemeron.org/~bigby/
                    news://news.ephemeron.org/alt.lemurs
    /-------------------------------------------------------------------------/

    _______________________________________________
    freebsd-security@freebsd.org mailing list
    http://lists.freebsd.org/mailman/listinfo/freebsd-security
    To unsubscribe, send any mail to "freebsd-security-unsubscribe@freebsd.org"


  • Next message: Ed Stover: "Re: Renaming root account"

    Relevant Pages

    • [UNIX] Security Vulnerabilities in OSF1/Tru64 3.x
      ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... locally exploitable buffer overflow which allows an attacker to gain root ... The executable is installed setuid root ... September 18, 2002 - Public Disclosure ...
      (Securiteam)
    • Re: Of mice and men
      ... any more than bank security is voluntary by the customers. ... With their own account, and guest accounts set up, I no longer have to worry about someone else screwing my work tools up. ... There are many programs that have in the past been used to exploit Linux - programs running as "root" even though you are just a plebian user. ... If you ask to run a program that uses root privleges "as a plebian user" it will tell you that you do not have disk access. ...
      (comp.lang.cobol)
    • Re: hi all..
      ... If you somehow had access to my account right now, ... install an effective key logger without root. ... Of course, if I have sudo ... the security of your system you should just reinstall. ...
      (Fedora)
    • Re: Account Hijacked
      ... Eventually pieced together what had happened from eBay security e-mails and the log of my seller account..... ... At 9.15pm eBay had spotted this. ... Took about an hour to understand what had happened, change my eBay & Paypal passwords, change my secret questions etc. Credit to eBay for a very clever ringback system - automated call gives you a one-time PIN to access & reset the account. ... My old password was medium secure, but would I'm sure be breakable by a serious attacker. ...
      (uk.people.consumers.ebay)
    • Re: How to Configure Qmail on Fedora Core 1 Server
      ... since the user foo would not have root privledges. ... that account is cracked they still are restricted on privileges. ... The security issue with reading mail as root via pop3 or imap is the ...
      (Fedora)