OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
From: Giacomo Cariello (jwkbug.it)
Date: Fri Feb 02 2001 - 19:41:16 CST

  • Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]

    >* If you connect to this machine via ssh and run sudo, you lose your user
    > account password to the attacker.

    Not if 'sudo' is configured not to ask passwords for that account. It's
    just the same as logging as root but it's more fine-shaped and you gain
    accountability.

    Just keep in mind private key issues with RSA authentication.

    Giacomo Cariello, jwkbug.it
    KeyID: 3072/1024/0x409C9044
    Fingerprint: 7984 10FD 0460 4202 BF90 3881 CDE4 D78E 409C 9044

    "Put that mic in my hand and let me kick out the jams!" - MC5