LinuxQuestions.org
Visit Jeremy's Blog.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 12-03-2003, 10:05 AM   #1
lapthorn
Member
 
Registered: Jul 2003
Location: Reading
Distribution: Red Hat
Posts: 89

Rep: Reputation: 16
rlogin as root without password


I need to be able to use rlogin as root over my work network. I know its a major security issue but neither machines have connections to the outside world.

I have allowed the rlogin service

Amended the /etc/securetty to include

rlogin
pts/0
pts/1

and restarted xinetd service.

My /etc/hosts.equiv file on <machineA> contains '<machineB> root'

When I attempt to rlogin from <MachineB> as root. It asks me to authenticate with a password. If I then type the password in access is granted.

If I change the hosts.equiv file to allow 'lapthorn' access to <MachineA> and attempt an rlogin, no password is needed.

I thought adding rlogin, pts/0, pts/1 into /etc/securetty would allow root to have access without password. Am I missing anything?


James
 
Old 12-04-2003, 12:46 PM   #2
PeterT
Newbie
 
Registered: Dec 2003
Location: Pasadena MD
Distribution: RedHat 9
Posts: 12

Rep: Reputation: 0
Have you considered using ssh/scp with exchanged keys? It will give you the same effect, no password required to login or copy files, but will do so relatively securely.

The man pages should cover this, and it's easy to set up.

I don't use the r* apps on linux, so I can't help you directly.
 
Old 02-05-2004, 05:24 PM   #3
jerry950
LQ Newbie
 
Registered: Feb 2004
Posts: 8

Rep: Reputation: 0
I have the same problem. I need to use rdist.
Did you ever get the anwser to this question?
 
Old 02-05-2004, 10:43 PM   #4
witeshark
Member
 
Registered: Jan 2004
Location: Miami FL
Distribution: Mac OS X 10.4.11 Ubuntu 12.04 LTS
Posts: 429

Rep: Reputation: 30
Exclamation Re: rlogin as root without password

Quote:
Originally posted by lapthorn

If I change the hosts.equiv file to allow 'lapthorn' access to <MachineA> and attempt an rlogin, no password is needed.

I thought adding rlogin, pts/0, pts/1 into /etc/securetty would allow root to have access without password. Am I missing anything?


James
Well I'm sure you will get an answer, but trying to make any machine root login without any password is not a great habit to develop. just my Anytime I see the motive to set up passwordless access, I have to winder why. If the password itself is such an annoying deal, maybe a few guildlines can help: NO use of birthday/backwards phone numbers/backward birthday -sister's year - mom's month and crap like that Try something like initials generated from things that you really like in life that no one could guess. racing-cars-rap music >> to F Fararri rap J Z --things like that. Choose something that's so easy to remember that you don't write it down EVER --what's worse then a total password compromised cause a bit of paper fell on to the floor! isn't this more helpful then defeating the password??

Last edited by witeshark; 02-05-2004 at 11:28 PM.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
How could normal user obtain root password or change root password ckamheng Debian 18 02-18-2009 10:28 PM
Booting into Single User on MDK 9 asks for root password instead of booting into root acadcworks Linux - General 6 01-10-2006 06:51 AM
Logged in as root, prompted for root password ta0kira Slackware 13 04-25-2005 01:29 AM
Cannot rlogin without password davepal Linux - Networking 4 04-21-2004 09:20 AM
Rlogin promts for password adme Linux - Networking 1 03-07-2003 12:19 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 05:06 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration