[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: [POSSIBLE GRAVE SECURITY HOLD]



In tom.lists.debian-devel, you wrote:
> > After all, with a boot prompt, the student could get root access using
> > init=/bin/sh  [Oh, wait, then that would be "grave" a bug in lilo..]

On Thu, Feb 03, 2000 at 03:57:18PM -0000, tom@hunt184-80.optonline.net wrote:
> Actually, not really. Lilo has two options ("restricted" and
> "password=") that, used together, allow the system to be booted
> without giving the user the ability to change the kernel command
> line. (Making lilo unreadable by users is a must so that they can't
> find out the password.)

Likewise, MBR has an option to prevent the boot prompt from being
functional.

I agree that there's a documentation issue here, by the way.

-- 
Raul


Reply to: