LinuxQuestions.org
Latest LQ Deal: Latest LQ Deals
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 12-18-2001, 09:59 PM   #1
system
Member
 
Registered: Dec 2001
Distribution: LFS, RH, Slack
Posts: 104

Rep: Reputation: 15
Flaw in su allows root access?


I am aware that RedHat comes set up to only allow root to log in through particular devices (eg. console). Root is not allowed to log in through telnet correct? But, I can log in as a user through telnet then su to become root!! Isn't this a security compromise? I realise it may be dependant upon having telnet open, but jeeze!! That seems like a BIG hole to me! It completely subverts the idea of restricting which devices root can log in on!
 
Old 12-18-2001, 11:02 PM   #2
system
Member
 
Registered: Dec 2001
Distribution: LFS, RH, Slack
Posts: 104

Original Poster
Rep: Reputation: 15
Here is some more interesting info on this: while logged in on telnet and using su to gain root acces, whoami returns "root", but users returns the username and not root.
 
Old 12-19-2001, 01:20 AM   #3
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
No it ain't strictly speaking, because su has no relation to telnet security-wise. OTOH if you're using PAM, you could protect from su usage by defining extra necessary authentication, like users to be in the "wheel" group to be able to use su at all.

The overruling and bigger compromise in this case would be effectively *using* telnetd on a box, because now you have transmitted all login name/passwd combo's/any data in cleartext over the 'net.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
libpng flaw rgiggs Slackware 4 08-06-2004 03:57 AM
Flaw in kernel 2.4.26 gstasica Linux - General 3 07-16-2004 03:27 PM
Updates/Flaw KooPA Linux - Security 5 04-27-2004 09:35 AM
a flaw is just a flaw jamaso General 1 03-25-2003 06:45 AM
wu-ftpd :serious flaw anoop_chandran Linux - General 3 12-11-2001 02:36 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 05:21 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration