Re: PermitRootLogin=yes versus su

From: Cameron Laird (claird@lairds.com)
Date: 01/31/03


From: claird@lairds.com (Cameron Laird)
Date: Fri, 31 Jan 2003 14:43:42 -0000

In article <3nvng-p4p.ln1@news.lairds.org>,
Kyler Laird <Kyler@news.Lairds.org> wrote:
                        .
                        .
                        .
>There are ways to mix the two approaches.
>
>PermitRootLogin is not tied to "root". It controls login by
>anyone with UID 0. You could easily make a "secretroot" account
>for use when logging in remotely. Leaving the "root" account
>around might be necessary for local use (like when a disk goes
>bad) though.
                        .
                        .
                        .
Oh, yes. I had a period when part of my hardening routine
was to change the name of root to 'serf' or 'lowlife' or
something equally impotent-looking. You're right--it would
have been, and is, wiser to add the undercover account as a
second UID 0, while retaining 'root'.

-- 
Cameron Laird <Cameron@Lairds.com>
Business:  http://www.Phaseit.net
Personal:  http://phaseit.net/claird/home.html


Relevant Pages

  • Re: PermitRootLogin=yes versus su
    ... >>>second UID 0, while retaining 'root'. ... A root called 'lowlife' makes me feel correspondingly ... Using "lowlife" for day to day UID 0 use while still having ... a "root" account that can be used, ...
    (comp.security.ssh)
  • Re: Rename root to avoid hacking?
    ... Those are remote attacks, ... root user by name, but I am absolutely certain that no system-local ones ... By using the UID instead of the username, ... ...reach exactly the same SMTP daemon welcome banner. ...
    (comp.os.linux.security)
  • Re[2]: accounting with ipfw (gid, uid riles)
    ... MS> The uid associated with a socket is the uid of the process which created ... it's still accounted to root. ... far, is adding alias interface, bind squid to this interface and count ...
    (FreeBSD-Security)
  • Re: PermitRootLogin=yes versus su
    ... >brute force attacks on the "root" account (other than against ... Instead of just having another UID 0 account that one ... >alert you if it's ever used through SSHd. ...
    (comp.security.ssh)
  • Re: Root is root no more
    ... > they required root access. ... > cchsu etc, cchsu being the first root uid account. ... > pwconv'd the file, added the passwd for these accounts, changed the $HOME ...
    (comp.unix.solaris)

Quantcast