LinuxSA Mailing list archives

Index: [thread] [date] [subject] [author] [stats]
  From: Vladimir V. Bashkirtsev <mega@konectanet.com.au>
  To  : Andrew Halliday <andrew@recalldesign.com>
<linuxsa@linuxsa.org.au> Date: Mon, 29 Jan 2001 20:33:57 +1030

Re: Changing the root user

>So my question is: is there any way to change WHO the root user is?  I
mean, I cant see that linux would be coded in such a way >that this would be
unretrenchably embedded in the system, since thats a bad coding
ethic...however I can forsee that because root is >an exceptional user,
there will be certain exceptions all over the place.

The problems is that standard define range of uids for different purpose
(0 - superuser, 1-499 - daemons, 500 and higher - real users). So you can
call your UID 0 with any name but it will not be more secure than with
root... You only will run into troubles when one of stupid programs which
runs under root (OK! UID 0) will set permissions or something else by hard
coded name (really bad ethic). No one of us knows how many programs with
such "bugs" we have.

>But just imagine it : someone living in the depths of Russia or something,
after having spent too much time on hacking my box

I came to SA from depths of Russia (Siberia - deep enough? :) just to hack
your box! :) I wondering that you think about russian ITs as about violent
people but be real: who got enough knowledge to hack your (or someone else)
box will be wise enough to think carefully before he will really violate
something. I agree that there is alot of violence on the streets (I had
chance to feel it :( ) but Runet is friendly enough.

Also think about who is a hacker's target? Big companies with alot of money.
So here nothing to worry for you.

>FINALLY gets root...only to discover that root has the eqivalent access
permissions of nobody and that this user called 'fred' or
>'sakjfhsdfgldfgkdfjgkdgskdjfhgdkjfhgadfkjhgaf' is the super-user!!!

You probably will have a problem to remeber such superuser name! :)

Vladimir


-- 
LinuxSA WWW: http://www.linuxsa.org.au/  IRC: #linuxsa on irc.linux.org.au
To unsubscribe from the LinuxSA list:
  mail linuxsa-request@linuxsa.org.au with "unsubscribe" as the subject


Index: [thread] [date] [subject] [author] [stats]
Return to the LinuxSA Mailing List Information Page