[aklug] Re: Security hole in installs of Ubuntu.

From: Joshua J. Kugler <joshua@eeinternet.com>
Date: Wed Aug 19 2009 - 08:42:25 AKDT

On Tuesday 18 August 2009, Christopher Howard said something like:
> Regarding the remote reboot problem: I wonder if anyone has ever
> thought of some way around that. I mean, if it is possible to enter a
> password at the terminal during boot time, then could there not
> possibly be some way to do it remotely? Perhaps we could somehow wrap
> a small ssh server into the initramfs, so that when the kernel booted
> and cryptsetup was run, it also could receive the password over the
> network.

An SSH server in the initramfs would be cool. Another "way around" is
something like Sun's ILOM
(http://www.sun.com/systemmanagement/ilom.jsp) where you have remote
access to a console on the box. Bascially, built-in KVM over IP. But
then, you have another attack vector, so make sure you lock your
management network down nice a secure. :)

j

-- 
Joshua Kugler
Part-Time System Admin/Programmer
http://www.eeinternet.com
PGP Key: http://pgp.mit.edu/  ID 0x14EA086E
---------
To unsubscribe, send email to <aklug-request@aklug.org>
with 'unsubscribe' in the message body.
Received on Wed Aug 19 08:42:38 2009

This archive was generated by hypermail 2.1.8 : Wed Aug 19 2009 - 08:42:38 AKDT