Protecting the Linux Root Password
Putting Passwords on GRUB and the BIOS
Last week's tip covered some ways of getting into a system when you don't have (or have forgotten) the root password. Obviously, being able to do this has disadvantages when the person doing it is an attacker trying to get at the system for nefarious reasons. (Or even users fiddling with the system without authorization.)
then type in the new password when prompted. A hash value looking something like this:
will be returned. Make a note of it, and exit GRUB.
Now edit /boot/grub/menu.lst, and add this line:
password --md5 $1$LfYJ1/$RZu3Ra2OYO8Cl9TvLsQqF.
(using the encrypted value GRUB gave you) before any of the boot menu entries, and you're done.
You can also prevent a particular boot entry from being booted without the password. Add the line:
after the title line in the relevant boot entry. To lock the recovery mode entries, it's preferable to change the linelockalternative=false to lockalternative=true: This will maintain the lockdown even if the kernel is updated.
This will not protect your system against boot from a LiveCD: To do this, edit the BIOS to remove the CD/DVD drive from the boot options, then password-protect it. Remember that if you forget this password, you won't be able to re-edit the BIOS if you do need to boot from a CD!
Finally, bear in mind that a serious attacker will not be thwarted by these measures. If you need more protection, look at your site's overall physical security, and consider encrypting your hard drives.
Article courtesy of Serverwatch
Solid state disks (SSDs) made a splash in consumer technology, and now the technology has its eyes on the enterprise storage market. Download this eBook to see what SSDs can do for your infrastructure and review the pros and cons of this potentially game-changing storage technology.
- 1Linux Top 3: GNOME 3.12 and New Betas for Ubuntu 14.04 and OpenMandriva Lx 2014.0
- 2Linux Top 3: Linux 3.10 Goes Long, Linux 3.11 Advances as LXDE Merges
- 3Linux Top 3: Linus Lashes out, Linux 3.14 Gets PIE and Ubuntu One is Done.
- 4Linux Top 3: Ubuntu 14.04, Debian Gives Squeeze More Life and Red Hat Goes Atomic
- 5Linux Top 3: Linux 3.11, Kubuntu Goes Commercial