[Full-disclosure] Putty Proxy login/password discolsure....

Paul Schmehl pauls at utdallas.edu
Wed Oct 25 20:16:32 BST 2006


--On Wednesday, October 25, 2006 23:57:15 +0530 Raj Mathur 
<raju at linux-delhi.org> wrote:

> On Wednesday 25 October 2006 23:14, cardoso wrote:
>> Exactly. A few years ago I used to deal with linux fanboys showing
>> them the cute trick of "linux single" at boot time. After a few
>> hours begging for the admin password, I teached the trick and they
>> usually stopped the brag about how security Linux was.
>
> Can't do that in most modern distributions today -- they're configured
> to ask for root password before they give a single-user shell.
>
> Not that there aren't other ways around that restriction...
>
Precisely - like booting from a Knoppix cd, mounting the drives rw....you 
get the picture.  Physical access == total access.  Worst case scenario, I 
simply remove the drives and mount them on a box that I do control.

Paul Schmehl (pauls at utdallas.edu)
Senior Information Security Analyst
The University of Texas at Dallas
http://www.utdallas.edu/ir/security/
-------------- next part --------------
A non-text attachment was scrubbed...
Name: not available
Type: application/pkcs7-signature
Size: 4085 bytes
Desc: not available
Url : http://lists.grok.org.uk/pipermail/full-disclosure/attachments/20061025/d65e3c9d/attachment.bin 


Full-Disclosure is hosted and sponsored by Secunia.