LinuxQuestions.org
Share your knowledge at the LQ Wiki.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 12-19-2004, 06:59 PM   #1
DJ Shaji
Member
 
Registered: Dec 2004
Location: Yo Momma's house
Distribution: Fedora Rawhide, ArchLinux
Posts: 518
Blog Entries: 15

Rep: Reputation: 106Reputation: 106
Exclamation "Pseudo" Installs - a new way to hack into a system?


I'm not techie, but I've done this, and I'm a little confused.

Consider this:

You have Red Hat Linux installed on a ext3 filesystem. Two people use this system - Steve and Dave. They each have a "normal" (non-root) account. Both cannot access each other's documents. However, if a person does a "pseudo" install on the system, he will supply a new root password and then he can access both Steve and Dave's documents without restriction.

On the other hand, if a new install is done on a computer running XP on an NTFS file system, overwriting the previous Windows installation, then the individual "My Documents" folders of all "Administrators" of the system will become "useless". Everyone is denied access to these folders, and the only way to delete them is to reformat the hard drive.

Any opinions? Does this mean the Tux cannot protect our documents, and Linux is vulnerable to "Pseudo install" attacks?
 
Old 12-19-2004, 08:39 PM   #2
Hangdog42
LQ Veteran
 
Registered: Feb 2003
Location: Maryland
Distribution: Slackware
Posts: 7,803
Blog Entries: 1

Rep: Reputation: 422Reputation: 422Reputation: 422Reputation: 422Reputation: 422
Re: "Pseudo" Installs - a new way to hack into a system?

Quote:
Originally posted by DJ Shaji


Any opinions? Does this mean the Tux cannot protect our documents, and Linux is vulnerable to "Pseudo install" attacks?
This isn't a "vulnerability" or some sort of attack, but rather the simple fact that if someone has physical access to your computer, you have no security. They could boot a CD-based distro like Knoppix, or simply boot into single user mode. With some distros, booting into single user mode automatically gives you root access. Security can only go so far, and physical access means a reasonably skilled person can defeat a number of normal security measures.
 
Old 12-19-2004, 09:45 PM   #3
2damncommon
Senior Member
 
Registered: Feb 2003
Location: Calif, USA
Distribution: PCLINUXOS
Posts: 2,918

Rep: Reputation: 103Reputation: 103
Quote:
...if someone has physical access to your computer, you have no security...
That is the simple truth.
You could disallow booting from floppy or CD and password protect your BIOS if you wanted to live in denial.
 
Old 12-19-2004, 09:52 PM   #4
Capt_Caveman
Senior Member
 
Registered: Mar 2003
Distribution: Fedora
Posts: 3,658

Rep: Reputation: 69
Not really sure what you mean by a pseudo install, but virtually all major OS's suffer from the local attacks Hangdog42 described, so it's definitely not a "Linux" thing. It's an unfortunately consequence of people forgetting root/admin passwords...if there's no way to reset it, then the user now has very expensive doorstop.

If you want to keep your files secure, encrypt them. Even then, it's often still possible to recover the data by recovering encryption keys from drives or if it's not stored on disk, they can even turn up in the swap partition.

Even the solutions that 2damncommon listed are defeatable.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
msyslog hack - stop the "last message repeated" insanity??? whysyn Linux - Software 1 04-26-2006 10:34 AM
"User" & "System" CPU load difference JJX Linux - General 3 06-06-2004 01:42 AM
"X-MS" cant open because "x-Multimedia System" cant access files at "smb&qu ponchy5 Linux - Networking 0 03-29-2004 11:18 PM
Pepsi iTunes "hack" witeshark General 4 02-23-2004 02:06 PM
RH "null" beta system freezes right after printing "INIT" markus1982 Linux - Hardware 0 09-09-2002 03:31 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 03:57 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration