this post was submitted on 12 Apr 2025
100 points (96.3% liked)

Linux

56009 readers
852 users here now

From Wikipedia, the free encyclopedia

Linux is a family of open source Unix-like operating systems based on the Linux kernel, an operating system kernel first released on September 17, 1991 by Linus Torvalds. Linux is typically packaged in a Linux distribution (or distro for short).

Distributions include the Linux kernel and supporting system software and libraries, many of which are provided by the GNU Project. Many Linux distributions use the word "Linux" in their name, but the Free Software Foundation uses the name GNU/Linux to emphasize the importance of GNU software, causing some controversy.

Rules

Related Communities

Community icon by Alpár-Etele Méder, licensed under CC BY 3.0

founded 6 years ago
MODERATORS
 

On a server I have a public key auth only for root account. Is there any point of logging in with a different account?

you are viewing a single comment's thread
view the rest of the comments
[–] ShortN0te@lemmy.ml 2 points 2 months ago (33 children)

The attacker that is currently with user privileges on the server?

[–] Lemmchen@feddit.org 9 points 2 months ago* (last edited 2 months ago) (22 children)

How did the attacker gain your user's privileges? Malware-infected user installation? A vulnerability in genuine software running as your user? In most scenarios these things only become worse when running as root instead.

[–] ShortN0te@lemmy.ml 7 points 2 months ago (21 children)

The scenario OC stated is that if the attacker has access to the user on the server then the attacker would still need the sudo password in order to get root privileges, contrary to direct root login where the attack has direct access to root privileges.

So, now i am looking into this scenario where the attack is on the server with the user privileges: the attacker now modifies for example the bashrc to alias sudo to extract the password once the user runs sudo.

So the sudo password does not have any meaningful protection, other then maybe adding a time variable which is when the user accesses the server and runs sudo

[–] grrgyle@slrpnk.net 1 points 2 months ago

Oh that's dastardly

load more comments (20 replies)
load more comments (20 replies)
load more comments (30 replies)