[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
RE: [cobalt-users] security
- Subject: RE: [cobalt-users] security
- From: Reinoud van Leeuwen <rvanleeuwen@xxxxxxxxxxxx>
- Date: Wed Feb 14 09:23:54 2001
- List-id: Mailing list for users to share thoughts on Cobalt products. <cobalt-users.list.cobalt.com>
> On Mon, 12 Feb 2001, Chris Mason wrote:
>
> } Correct my thinking here but if you are hosting a raq in a
> colo or dedicated
> } facility, and you telnet in with admin account, anyone with
> another machine
> } can run a sniffer, see your admin password, use it to get
> to root, and crack
> } your machine.
> } SSH only.
>
> You are right. Unless the network is segmented by a switch
> anyone with root access on any of the machines on that network can
> sniff all the packets on that network - including your packets.
Do not rely on a switch. I've seen people turnig a switch into a
broadcasting hub.