Linode.com Forum Forum Index Linode.com Forum
Linode Community Forums
 


forbid root login to lish?

Click here to go to the original topic

 
       Linode.com Forum Forum Index -> Linux, Apache, Mysql and PHP (LAMP) Forum
Author Message
cattani



Joined: 01 Jan 2008
Posts: 15

Posted: Tue Jan 01, 2008 10:34 am    Post subject: forbid root login to lish?  

hy,
i disabled root login with ssh. is there a way to limit lish login too?
thanks
Back to top  
Stever



Joined: 07 Dec 2007
Posts: 41
Location: NC, USA

Posted: Tue Jan 01, 2008 11:03 am    Post subject:  

Maybe remove tty0 from /etc/securetty?
I think this should prevent root logins, but if they have already managed to login to lish you are probably completely pwned anyway.
Back to top  
cattani



Joined: 01 Jan 2008
Posts: 15

Posted: Tue Jan 01, 2008 11:23 am    Post subject:  

removing tty0 means every user except root can log in, but every user can do a su - and become root, right? i have vc/0 - 11 and tty0 - 11 in the file, whats that? i thought vc is an alias for tty?

i want to do it because this way one has to break two passwords to gain root access.
Back to top  
Stever



Joined: 07 Dec 2007
Posts: 41
Location: NC, USA

Posted: Tue Jan 01, 2008 11:38 am    Post subject:  

cattani wrote: removing tty0 means every user except root can log in, but every user can do a su - and become root, right? this way one has to break two passwords to gain root access.
Yes, anyone but root could login through the console, and then they could su from there if they are normally allowed to. Really this would require three passwords - lish, regular user, root.
However if they can login to lish, that means they can access your account and do pretty much anything they want, for example installing and booting into a new disk image, or canceling your account. Probably no limit to the BadThings they could do with that one password.
Back to top  
cattani



Joined: 01 Jan 2008
Posts: 15

Posted: Tue Jan 01, 2008 11:45 am    Post subject:  

hmm, so i need to disable lish, any idea how to? thanks!
Back to top  
anderiv



Joined: 27 Apr 2004
Posts: 127

Posted: Tue Jan 01, 2008 2:35 pm    Post subject:  

cattani wrote: hmm, so i need to disable lish, any idea how to? thanks!
If you do this, how would you plan on gaining access to your linode if, say, networking wasn't working for some reason, or if sshd broke?

Your best solution is to do as suggested, edit /etc/securetty and use very strong passwords.
Back to top  
Internat



Joined: 17 Aug 2004
Posts: 172
Location: Brisbane, Australia

Posted: Tue Jan 01, 2008 2:59 pm    Post subject:  

If they know your lish password, they can log into the members section of linode, and say reboot into finnix and change ur passwords/security options reboot, and then have full access to your stuff there. so.. Its probably not worth thinking about disabling lish. Just make sure ur password for linode.com is strong
Back to top  
 
       Linode.com Forum Forum Index -> Linux, Apache, Mysql and PHP (LAMP) Forum
Page 1 of 1