Re: changing root account name

From: Jose Nazario (jose@biocserver.BIOC.cwru.edu)
Date: 10/30/01


Date: Tue, 30 Oct 2001 17:25:07 -0500 (EST)
From: Jose Nazario <jose@biocserver.BIOC.cwru.edu>
To: Kurt Yoder <kylist@shcorp.com>
Subject: Re: changing root account name
Message-ID: <Pine.LNX.4.30.0110301723030.32481-100000@biocserver.BIOC.CWRU.Edu>

On Tue, 30 Oct 2001, Kurt Yoder wrote:

> Would there be any benefit in changing the account name of "root"? For
> instance, I could change the uid 0 account to have the name "foobar".
> Then, if someone were trying to break into the root account, they
> would have an additional step; instead of logging in as root, they'd
> first have to find out what the uid 0 account was called. Of course,
> "su" would always work, but an attempted root login via the network
> would be more difficult, right?

there are far more efficient ways to getting uid zero access rather than
using ssh target -l root or whatever. just smash a stacke or format your
own string on a process running as uid 0 and voila, you are uid 0.

changing the uid 0 login name is hardly worth doing. besides, a few pieces
of low quality software may expect uid 0 == root and hardcode that. your
move may break that.

hope that helps,

____________________________
jose nazario jose@cwru.edu
                           PGP: 89 B0 81 DA 5B FD 7E 00 99 C3 B2 CD 48 A0 07 80
                                       PGP key ID 0xFD37F4E5 (pgp.mit.edu)



Relevant Pages

  • Re: Rename root to avoid hacking?
    ... Those are remote attacks, ... root user by name, but I am absolutely certain that no system-local ones ... By using the UID instead of the username, ... ...reach exactly the same SMTP daemon welcome banner. ...
    (comp.os.linux.security)
  • Re[2]: accounting with ipfw (gid, uid riles)
    ... MS> The uid associated with a socket is the uid of the process which created ... it's still accounted to root. ... far, is adding alias interface, bind squid to this interface and count ...
    (FreeBSD-Security)
  • Re: root account deleted
    ... root account. ... equivalent) entry for UID 0 has been removed? ... Lew Pitcher ...
    (alt.os.linux.suse)
  • RE: Renaming root account
    ... Enabling "toor" is not very different from renaming the root account, ... because you would then have two "root" (uid 0) accounts. ... I don't see any harm in renaming the root account, but I don't think it would ...
    (FreeBSD-Security)
  • Re: Root is root no more
    ... > they required root access. ... > cchsu etc, cchsu being the first root uid account. ... > pwconv'd the file, added the passwd for these accounts, changed the $HOME ...
    (comp.unix.solaris)