home *** CD-ROM | disk | FTP | other *** search
- Newsgroups: comp.unix.ultrix
- Path: sparky!uunet!cs.utexas.edu!zaphod.mps.ohio-state.edu!sol.ctr.columbia.edu!The-Star.honeywell.com!umn.edu!lynx!fmsrl7!e3u001!ed8217.ped.pto.ford.com!cannell
- From: cannell@ed8217.ped.pto.ford.com (Larry Cannell)
- Subject: Re: Decstation Ultrix single-user mode security hole.
- Message-ID: <1992Aug22.203628.16577@e3u001.ped.pto.ford.com>
- Keywords: DecStation, Ultrix, Security Hole, Help
- Sender: root@e3u001.ped.pto.ford.com (System PRIVILEGED Account)
- Organization: Powertrain Electronics, Ford Motor Co.
- References: <ZAPHOD.92Aug22032228@splinter.coe.northeastern.edu>
- Distribution: comp
- Date: Sat, 22 Aug 1992 20:36:28 GMT
- Lines: 18
-
- In article <ZAPHOD.92Aug22032228@splinter.coe.northeastern.edu> zaphod@splinter.coe.northeastern.edu (Erik Lloyd Bunce) writes:
- >
- > On Decstations running Ultrix 4.1-4.2a is there any way to
- >make it so that users can't just hit ^C during the multiuser boot
- >process to break into single-user mode? (and thus get access as root
- >on the machine). Changing /etc/ttys and setting the prom password
- >doesn't seem to prevent this easy breach of security. Any Ideas or
- >suggestions would be appreciated.
- >
-
- We had the same concerns.
-
- Check the Ultrix release notes. They give examples of what changes are
- necessary to /etc/rc.
-
- Larry Cannell
- Powertrain Electronics
- Ford Motor Co.
-