pam_tally --> deny doesnt seem to work when magic_root
Linux - SecurityThis forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.
Notices
Welcome to LinuxQuestions.org, a friendly and active Linux Community.
You are currently viewing LQ as a guest. By joining our community you will have the ability to post topics, receive our newsletter, use the advanced search, subscribe to threads and access many other special features. Registration is quick, simple and absolutely free. Join our community today!
Note that registered members see fewer ads, and ContentLink is completely disabled once you log in.
magic_root
If the module is invoked by a user with uid=0 the counter is not incremented. The sys-admin should use this for user launched services, like su, otherwise this argument should be omitted.
Now, faillog gets updated and also the account gets locked after 3 failed login attempts...
I am afraid, if this would 'lock' -> "root" also.
So I tested to check, if root gets locked after 3 failed login attempts
and indeed I was puzzled to see "root" alone is not "lockedout" after even 15 failed login attempts...
I am confused.. with this...
Is this behaviour ...? Can I trust this... against DOS attacks...
LinuxQuestions.org is looking for people interested in writing
Editorials, Articles, Reviews, and more. If you'd like to contribute
content, let us know.