home *** CD-ROM | disk | FTP | other *** search
- Xref: sparky comp.unix.ultrix:6408 comp.unix.admin:4638
- Path: sparky!uunet!olivea!mintaka.lcs.mit.edu!chaos!splinter.coe.northeastern.edu
- From: zaphod@splinter.coe.northeastern.edu (Erik Lloyd Bunce)
- Newsgroups: comp.unix.ultrix,comp.unix.admin
- Subject: Decstation Ultrix single-user mode security hole.
- Keywords: DecStation, Ultrix, Security Hole, Help
- Message-ID: <ZAPHOD.92Aug22032228@splinter.coe.northeastern.edu>
- Date: 22 Aug 92 07:22:28 GMT
- Sender: usenet@chaos.DAC.Northeastern.edu
- Followup-To: comp.unix.ultrix
- Distribution: comp
- Organization: College of Engineering, Northeastern University
- Lines: 33
-
-
- On Decstations running Ultrix 4.1-4.2a is there any way to
- make it so that users can't just hit ^C during the multiuser boot
- process to break into single-user mode? (and thus get access as root
- on the machine). Changing /etc/ttys and setting the prom password
- doesn't seem to prevent this easy breach of security. Any Ideas or
- suggestions would be appreciated.
-
- -------------------------------------------------------------------------------
- |Erik L. Bunce |
- |Bunce and Coveney Co. |
- |zaphod@meceng.coe.northeastern.edu |
- |-----------------------------------------------------------------------------|
- | This is a test. |
- | This is only a test. |
- | If this were a real life, |
- | You would have been given instructions. |
- | You are experiencing a pirated copy of a life, |
- | Ergo. No manual. |
- -------------------------------------------------------------------------------
- | My opinions are my employers, but not necessarily Northeastern University's.|
- -------------------------------------------------------------------------------
- --
- -------------------------------------------------------------------------------
- |Erik L. Bunce | This is a test. |
- |Bunce and Coveney Co. | This is only a test. |
- |(617) 389-9068 | If this were a real life, |
- | | You would have been given instructions. |
- | | You are experiencing a pirated copy of a life, |
- | | Ergo. No manual. |
- -------------------------------------------------------------------------------
- | My opinions are my employers, but not necessarily Northeastern University's.|
- -------------------------------------------------------------------------------
-