[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

RE: [cobalt-users] security



> On Mon, 12 Feb 2001, Chris Mason wrote:
> 
> } Correct my thinking here but if you are hosting a raq in a 
> colo or dedicated
> } facility, and you telnet in with admin account, anyone with 
> another machine
> } can run a sniffer, see your admin password, use it to get 
> to root, and crack
> } your machine.
> } SSH only.
> 
> 	You are right. Unless the network is segmented by a switch
> anyone with root access on any of the machines on that network can
> sniff all the packets on that network - including your packets.

Do not rely on a switch. I've seen people turnig a switch into a
broadcasting hub.