home *** CD-ROM | disk | FTP | other *** search
- Path: sparky!uunet!usc!cs.utexas.edu!swrinde!sdd.hp.com!hp-cv!hp-pcd!hpfcso!rdg
- From: rdg@hpfcso.FC.HP.COM (Rob Gardner)
- Newsgroups: comp.sys.hp
- Subject: Re: HP 9000/370, no root password!
- Message-ID: <7371301@hpfcso.FC.HP.COM>
- Date: 9 Sep 92 19:59:08 GMT
- References: <1992Aug15.022529.7176@mccc.edu>
- Organization: Hewlett-Packard, Fort Collins, CO, USA
- Lines: 16
-
-
- > One question about this thread: Does physical access to a
- > _diskless_ workstation form any serious security risk?
- > Besides the danger of someone carrying the thing away, that is. :-)
- >
- > Well, you can fake the diskless protocol, pretend to be booting, and
- > start accessing file systems. Of course, this is possible anyway if
- > you know the hardware address of one diskless machine that happens to
- > be down, and have access to the cable.
-
- Heck, it's much easier than that. Just boot the system with the kernel
- debugger and you can do whatever you want! Um, well, it does require
- some advanced knowledge ;-)
-
-
- Rob
-