Compromise of the nobody account?
- From: mike3 <mike4ty4@xxxxxxxxx>
- Date: Sat, 26 Jan 2008 16:13:46 -0800 (PST)
Hi.
How bad it is it if one can't trust the "nobody" account on a UNIX or
Unix-like system, and said account has been broken into and is being
used to access the system? Should one just dump the account, then? Is
it bad practice to leave the "nobody" account unguarded?
At worst I'd guess the cracker might be able to turn off or fuss
around with daemons running as that, however if one uses something
else to run the daemons instead I would not think all that much damage
to the system could be done from a comp'd nobody account.
Is this a good assessment?
.
- Follow-Ups:
- Re: Compromise of the nobody account?
- From: Moe Trin
- Re: Compromise of the nobody account?
- From: Grant
- Re: Compromise of the nobody account?
- Prev by Date: Ethical hacking tutorial notes
- Next by Date: Re: Compromise of the nobody account?
- Previous by thread: Ethical hacking tutorial notes
- Next by thread: Re: Compromise of the nobody account?
- Index(es):
Relevant Pages
|