|
|||||||||||
|
RE: security scenario
From: Trevor Cushen <Trevor.Cushen(at)sysnet.ie>
Date: Fri Jan 31 2003 - 14:03:36 EST
Physical security is in place, root access is via console only (all previously discussed) A user can gain access via the lan (as part of their job) and places netcat (which is most likely already there on most Linux installs anyway). They then schedule overnight a dd of the system disk to a disk in their machine over the network (very easy to do) What priviledges do they need?? I must check this but I have a feeling they will have access to /dev files and also the /bin files where netcat and dd are (or /sbin). Now they can bring the newly cloned disk home and in their own time brute force root passwords, or boot via CDROM to by-pass the password and gain access to data. Very much possible and infact quite easy to do (I use it for forensics investigations where I can't shutdown the machine), clone a machine over a network connection. Your physical server room security is useless and also your root at console only security. Your bios passwords are useless here too as is your grub password. The point I am making here is that you have to match the solution to the environment so there will never be a true solution for all because all environments are different.
Trevor Cushen
www.sysnet.ie
-----Original Message-----
Well , I think that instead of dealing with how many layers one can install (and taking the time to install them) it is better (IMHO) to invest the time in making the important layers secure. having more layers won't increase your security level if you spent all the time in installing those same layers , whatmore , you have more then CDROM and Floppy to boot with (USB dev , etc...). I wouldnt use a grub password , or a bios password , as forgeting those , will cause more harm then the security benefit they provide ,writing them down or putting weak passwords is simply not worth the trouble . TheOg
> >From: "theog" <theog@theog.org>
> >anything, in fact, the simplest thing to do (if I wanted to change
> >so ..... no point is having a grub password for the machine if you
> an uninviting target, and become hack resistant. You have to draw the
> line somewhere or your administrative burden will grow greater than
> you start taking your computer apart and you don't work in IT. On top
> of this, removing the CD-ROM drive and Floppy drive from any
This email and any files transmitted with it are confidential and intended solely for the use of the individual or entity to whom they are addressed. If you have received this message in error please notify SYSNET Ltd., at telephone no: +353-1-2983000 or postmaster@sysnet.ie Received on Fri Jan 31 19:12:51 2003 This archive was generated by hypermail 2.1.8 : Wed Aug 23 2006 - 14:03:40 EDT |
||||||||||
|
|||||||||||