this post was submitted on 12 Apr 2025
100 points (96.3% liked)

Linux

53032 readers
350 users here now

From Wikipedia, the free encyclopedia

Linux is a family of open source Unix-like operating systems based on the Linux kernel, an operating system kernel first released on September 17, 1991 by Linus Torvalds. Linux is typically packaged in a Linux distribution (or distro for short).

Distributions include the Linux kernel and supporting system software and libraries, many of which are provided by the GNU Project. Many Linux distributions use the word "Linux" in their name, but the Free Software Foundation uses the name GNU/Linux to emphasize the importance of GNU software, causing some controversy.

Rules

Related Communities

Community icon by Alpár-Etele Méder, licensed under CC BY 3.0

founded 5 years ago
MODERATORS
 

On a server I have a public key auth only for root account. Is there any point of logging in with a different account?

you are viewing a single comment's thread
view the rest of the comments
[–] [email protected] 1 points 2 days ago (33 children)

The attacker that is currently with user privileges on the server?

[–] [email protected] 9 points 2 days ago* (last edited 2 days ago) (22 children)

How did the attacker gain your user's privileges? Malware-infected user installation? A vulnerability in genuine software running as your user? In most scenarios these things only become worse when running as root instead.

[–] [email protected] 7 points 2 days ago (21 children)

The scenario OC stated is that if the attacker has access to the user on the server then the attacker would still need the sudo password in order to get root privileges, contrary to direct root login where the attack has direct access to root privileges.

So, now i am looking into this scenario where the attack is on the server with the user privileges: the attacker now modifies for example the bashrc to alias sudo to extract the password once the user runs sudo.

So the sudo password does not have any meaningful protection, other then maybe adding a time variable which is when the user accesses the server and runs sudo

[–] [email protected] 1 points 1 day ago

Oh that's dastardly

load more comments (20 replies)
load more comments (20 replies)
load more comments (30 replies)