Re: User access & security



Mark wrote:
This is a question related to my next post.

If there is a user with non-root access to their account, we are
dependent on their having a good password to ward off too much nasty
activity.

Ok... easy to ensure and pretty secure.


I am told that it is fairly easy with user access to install a rootkit
of some sort and totally compromise the system.

No. It is not easy.. at least it's not supposed to be easy.


Now it seems to me that if this user is careless with this password,
then the whole server is at risk. How true is this? Doesn't this weaken
Linux to such an extent that any user access at all is guaranteed to
bring down the server.

A user account can cause issues... especially if there are no limits
on the account... but compromise? Again, much, much more difficult.


If that is the case, what do ISPs do, with their thousands of ordinary
users? What does anybody do?

Restrict them so that they can't adversely affect the whole machine
with regards to resource consumption. Even if somebody else logs
in... it's not different than the actual user as far as the
ISP is concerned.


I ask this because I have inadvertently left an account open with a
trivial password which somebody has stumbled into. (It has since been
closed, but the question remains).

My guess... is that unless the box was not setup well, that everything
is ok. The only damage would be to your infrastructure, files and
possibly your reputation.


Thanks,

Mark
.



Relevant Pages

  • Re: Dedicated service servers
    ... Most ISPs I know will have a dedicated web server and ... Most ISPs need you to explicitly choose to use their free webspace or not. ... option triggers the setup of an actual account on the webserver ... ... I think the NFS mount will fail in that instance, ...
    (Fedora)
  • Re: Re-Post - "the trust relationship between this workstation and the
    ... "the trust relationship between this workstation and the primary domain ... only problem is adding a new user account on the station. ... Client computer must use STRICTLY the INTERNAL DNS server which can ... Attr: subschemaSubentry ...
    (microsoft.public.windows.server.active_directory)
  • Re: Same question, still no answer!!!
    ... Sounds then like we are all paying for a feature set only large companies ... The "proxy server" pc is actually an older box stuffed ... Expectation #1) keep the ethernet more or less as is. ... The kids account would be ...
    (microsoft.public.windowsxp.basics)
  • Re: Re-Post - "the trust relationship between this workstation and the
    ... "the trust relationship between this workstation and the primary domain ... only problem is adding a new user account on the station. ... This would be on the DNS server 172.20.100.2 ... Attr: subschemaSubentry ...
    (microsoft.public.windows.server.active_directory)
  • Sending email to mydomain.com
    ... server will appear as undeliverable. ... This happens because you are using the POP3 connector... ... an NDR when an account doesn't exist). ... >different from the user account names for the exchange ...
    (microsoft.public.windows.server.sbs)