Home page logo
/

fulldisclosure logo Full Disclosure mailing list archives

Re: Ubuntu 11.10 now unsecure by default
From: Darren Martyn <d.martyn.fulldisclosure () gmail com>
Date: Fri, 18 Nov 2011 14:19:26 +0000

About time someone mentioned that little bit of information...

On Fri, Nov 18, 2011 at 2:10 PM, Dan Kaminsky <dan () doxpara com> wrote:



On Fri, Nov 18, 2011 at 5:01 AM, <Valdis.Kletnieks () vt edu> wrote:

On Thu, 17 Nov 2011 15:53:41 CST, C de-Avillez said:

There is no guest account on an Ubuntu server, so at least there
this is not a real/perceived risk.

And nobody's *ever* installed the desktop version on a server because
they didn't
know any better, especially from Ubuntu's target audience.  Gotcha. ;)


OK, seriously.  If you're sitting in front of a machine that's presenting
you a login prompt, you've got enough privileges to insert a bootable
USB/CD and pull all the data / make yourself an account (FDE/Bios PW
notwithstanding).



_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/



_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/




-- 
My Homepage :D <http://compsoc.nuigalway.ie/%7Einfodox>
_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/

  By Date           By Thread  

Current thread:
[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]