[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [cobalt-users] root password on RaQ4



Jamie wrote the last part:
> aware that you're being attacked...:) Make strong passwords.
>
> see ya,
> Diana

If the bad guy does find the hidden user in the GUI, the GUI still allows
Admin to change the users pass with out the need of knowing the old
password..  Granted, they have to find the user first, but a dedicated
hacker would eventually find it...

-Jamie-
http://w-c.net
WebConnection.Net, Inc.

Hi,

You're totally right...admin can change anyone's password, but out of the hundreds of users on the system in the hundred or so domains..hopefully the bad guy won't locate that special user very easily...:) It doesn't have to be a siteadmin or even have its home at the server base...:) I know we're beating a hypothetical horse here...:) Again, this is just my small attempt to make even the little things more difficult for a potential hacker. And, it does seem to me to make more sense than just changing root's password so that it's different than admin's. And not at all hard to do, and it may give pause to someone who thinks they've found a Cobalt machine knowing that admin's are by default the all important user. I may implement Steve Werby's cool technique for "moving" the admin control panel too...:) so much to do..:)

see ya,
Diana
Crest Communications, Inc.		diana@xxxxxxxxxxxxx
Beautiful Sunny Florida		http://crestcommunications.com/
352-495-9359, 425-732-9785 fax