lists.openwall.net   lists  /  announce  owl-users  owl-dev  john-users  john-dev  passwdqc-users  yescrypt  popa3d-users  /  oss-security  kernel-hardening  musl  sabotage  tlsify  passwords  /  crypt-dev  xvendor  /  Bugtraq  Full-Disclosure  linux-kernel  linux-netdev  linux-ext4  linux-hardening  linux-cve-announce  PHC 
Open Source and information security mailing list archives
 
Hash Suite: Windows password security audit tool. GUI, reports in PDF.
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Date: Mon, 21 Jul 2008 18:21:13 -0500
From: Paul Schmehl <pschmehl_lists@...rr.com>
To: full-disclosure@...ts.grok.org.uk
Subject: Re: help: I need to crack my box

--On Monday, July 21, 2008 22:47:26 +0200 Lucio Crusca <lucio@...web.org> wrote:

> Believe it or not, I have a linux box (mine, yes it's mine) I need to own...
> the problem is that it phisically resides a few 100km from here and someone
> else has changed the root password... I can still log in as luser and I
> wonder if I have a chance to become root again. It's a more or less current
> debian lenny i386 with gnome. Have you got anything for me?

Ask the hosting company if they have an ipkvm they can connect to the box.  If 
they do, you can reboot and go into single user mode and reset the root 
password.  I would then take down the net interfaces until you clean the box. 
Otherwise your info might be disclosed while you're working on it.

If you can't reboot it remotely, have their staff reboot it for you while 
you're logged in to the ipkvm.  Then get into single user mode and regain 
control of the box.

-- 
Paul Schmehl
As if it wasn't already obvious,
my opinions are my own and not
those of my employer.

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/

Powered by blists - more mailing lists

Powered by Openwall GNU/*/Linux Powered by OpenVZ