Re: [Full-disclosure] Root password change
- From: Michael Holstein <michael.holstein@xxxxxxxxxxx>
- Date: Fri, 31 Mar 2006 09:21:13 -0500
Trivial to defeat. Just boot in to single user mode with these kernel
options:
single init=/bin/bash
Again .. only due to initial misconfiguration.
Nobody should allow alternate switches to be passed to the kernel at boot .. either by password-protecting the bootloader, or via firmware (as with OpenBoot).
/mike.
_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/
- Follow-Ups:
- Re: [Full-disclosure] Root password change
- From: Valdis . Kletnieks
- Re: [Full-disclosure] Root password change
- References:
- [Full-disclosure] Root password change
- From: Mockbee, Tom
- Re: [Full-disclosure] Root password change
- From: Michael Holstein
- Re: [Full-disclosure] Root password change
- From: spam
- Re: [Full-disclosure] Root password change
- From: Kerry Thompson
- Re: [Full-disclosure] Root password change
- From: Gary E. Miller
- [Full-disclosure] Root password change
- Prev by Date: Re: [Full-disclosure] A Move to Remove
- Next by Date: [Full-disclosure] Claroline <= 1.7.4 (scormExport.inc.php) Remote Code Execution Exploit by rgod
- Previous by thread: Re: [Full-disclosure] Root password change
- Next by thread: Re: [Full-disclosure] Root password change
- Index(es):
Relevant Pages
|