<?xml version="1.0" encoding="UTF-8"?><rss
version="2.0"
xmlns:content="http://purl.org/rss/1.0/modules/content/"
xmlns:dc="http://purl.org/dc/elements/1.1/"
xmlns:atom="http://www.w3.org/2005/Atom"
xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
> <channel><title>Comments on: Tips To Protect Linux Servers Physical Console Access</title> <atom:link href="http://www.cyberciti.biz/tips/tips-to-protect-linux-servers-physical-console-access.html/feed" rel="self" type="application/rss+xml" /><link>http://www.cyberciti.biz/tips/tips-to-protect-linux-servers-physical-console-access.html</link> <description>This is a Linux sys admin journal by Vivek about sys admin work, Linux tips &#38; tricks, hacks, news and more.</description> <lastBuildDate>Fri, 10 Feb 2012 20:37:43 +0000</lastBuildDate> <sy:updatePeriod>hourly</sy:updatePeriod> <sy:updateFrequency>1</sy:updateFrequency> <generator>http://wordpress.org/?v=3.3.1</generator> <item><title>By: The lul</title><link>http://www.cyberciti.biz/tips/tips-to-protect-linux-servers-physical-console-access.html#comment-177506</link> <dc:creator>The lul</dc:creator> <pubDate>Sun, 25 Dec 2011 20:58:04 +0000</pubDate> <guid
isPermaLink="false">http://www.cyberciti.biz/tips/?p=4490#comment-177506</guid> <description>Encrypting the hard drive is quite necessary and also keeping backup on a remove server. Deja Dup does a great job for that !</description> <content:encoded><![CDATA[<p>Encrypting the hard drive is quite necessary and also keeping backup on a remove server. Deja Dup does a great job for that !</p> ]]></content:encoded> </item> <item><title>By: Chris</title><link>http://www.cyberciti.biz/tips/tips-to-protect-linux-servers-physical-console-access.html#comment-170651</link> <dc:creator>Chris</dc:creator> <pubDate>Sat, 16 Apr 2011 03:14:57 +0000</pubDate> <guid
isPermaLink="false">http://www.cyberciti.biz/tips/?p=4490#comment-170651</guid> <description>Nice post. It&#039;s good with the fullblown descriptions.</description> <content:encoded><![CDATA[<p>Nice post. It&#8217;s good with the fullblown descriptions.</p> ]]></content:encoded> </item> <item><title>By: Chalu</title><link>http://www.cyberciti.biz/tips/tips-to-protect-linux-servers-physical-console-access.html#comment-168777</link> <dc:creator>Chalu</dc:creator> <pubDate>Tue, 15 Feb 2011 22:05:20 +0000</pubDate> <guid
isPermaLink="false">http://www.cyberciti.biz/tips/?p=4490#comment-168777</guid> <description>Hi Guys..! can anyone guide me how to disable editing by using &quot;e&quot; while booting. means while booting we can able to enter into single user mode by pressing ESC key at spalsh image and selecting &quot; kernel /vmlinuz-2.6......&quot; and by pressing &quot;e&quot; key we can able edit. so can any one guide me how to disable this editing..
Thanks in advance
Chalu</description> <content:encoded><![CDATA[<p>Hi Guys..! can anyone guide me how to disable editing by using &#8220;e&#8221; while booting. means while booting we can able to enter into single user mode by pressing ESC key at spalsh image and selecting &#8221; kernel /vmlinuz-2.6&#8230;&#8230;&#8221; and by pressing &#8220;e&#8221; key we can able edit. so can any one guide me how to disable this editing..</p><p>Thanks in advance<br
/> Chalu</p> ]]></content:encoded> </item> <item><title>By: The Gripmaster</title><link>http://www.cyberciti.biz/tips/tips-to-protect-linux-servers-physical-console-access.html#comment-161914</link> <dc:creator>The Gripmaster</dc:creator> <pubDate>Wed, 08 Dec 2010 05:20:36 +0000</pubDate> <guid
isPermaLink="false">http://www.cyberciti.biz/tips/?p=4490#comment-161914</guid> <description>Disable CDROM/DVDROM boot completely in the BIOS and protect your BIOS with a password.</description> <content:encoded><![CDATA[<p>Disable CDROM/DVDROM boot completely in the BIOS and protect your BIOS with a password.</p> ]]></content:encoded> </item> <item><title>By: Harsha</title><link>http://www.cyberciti.biz/tips/tips-to-protect-linux-servers-physical-console-access.html#comment-158771</link> <dc:creator>Harsha</dc:creator> <pubDate>Mon, 09 Aug 2010 14:39:00 +0000</pubDate> <guid
isPermaLink="false">http://www.cyberciti.biz/tips/?p=4490#comment-158771</guid> <description>Thank u  Vivek. This info is really cool.</description> <content:encoded><![CDATA[<p>Thank u  Vivek. This info is really cool.</p> ]]></content:encoded> </item> <item><title>By: Ashwani</title><link>http://www.cyberciti.biz/tips/tips-to-protect-linux-servers-physical-console-access.html#comment-148269</link> <dc:creator>Ashwani</dc:creator> <pubDate>Thu, 23 Apr 2009 10:23:29 +0000</pubDate> <guid
isPermaLink="false">http://www.cyberciti.biz/tips/?p=4490#comment-148269</guid> <description>Thanks for very nice info
but can u pls explain me what is    ~~     this? as u said its id but i really dont about this id dear vivek pls tell us about this
Thanks</description> <content:encoded><![CDATA[<p>Thanks for very nice info</p><p>but can u pls explain me what is    ~~     this? as u said its id but i really dont about this id dear vivek pls tell us about this</p><p>Thanks</p> ]]></content:encoded> </item> <item><title>By: entplex</title><link>http://www.cyberciti.biz/tips/tips-to-protect-linux-servers-physical-console-access.html#comment-148236</link> <dc:creator>entplex</dc:creator> <pubDate>Tue, 21 Apr 2009 22:28:37 +0000</pubDate> <guid
isPermaLink="false">http://www.cyberciti.biz/tips/?p=4490#comment-148236</guid> <description>@Akshay: as far as preventing people from being able to boot to other media, the only thing you can do is use the bios settings to give the hard drive priority and in the case of some bios&#039;, you can disable booting to other media all together.  Obviously in order for this to have any effect, you need to implement a bios password (as was mentioned in this article).</description> <content:encoded><![CDATA[<p>@Akshay: as far as preventing people from being able to boot to other media, the only thing you can do is use the bios settings to give the hard drive priority and in the case of some bios&#8217;, you can disable booting to other media all together.  Obviously in order for this to have any effect, you need to implement a bios password (as was mentioned in this article).</p> ]]></content:encoded> </item> <item><title>By: cracker</title><link>http://www.cyberciti.biz/tips/tips-to-protect-linux-servers-physical-console-access.html#comment-148036</link> <dc:creator>cracker</dc:creator> <pubDate>Tue, 07 Apr 2009 14:44:07 +0000</pubDate> <guid
isPermaLink="false">http://www.cyberciti.biz/tips/?p=4490#comment-148036</guid> <description>why u post this anyway .....
then the world of gnu/ linux will be secure
:(</description> <content:encoded><![CDATA[<p>why u post this anyway &#8230;..<br
/> then the world of gnu/ linux will be secure<br
/> :(</p> ]]></content:encoded> </item> <item><title>By: Vivek Gite</title><link>http://www.cyberciti.biz/tips/tips-to-protect-linux-servers-physical-console-access.html#comment-147903</link> <dc:creator>Vivek Gite</dc:creator> <pubDate>Mon, 30 Mar 2009 11:46:34 +0000</pubDate> <guid
isPermaLink="false">http://www.cyberciti.biz/tips/?p=4490#comment-147903</guid> <description>Type the following to disable it:
&lt;code&gt;echo &#039;kernel.sysrq=0&#039; &gt;&gt; /etc/sysctl.conf
sysctl -p&lt;/code&gt;
See this &lt;a href=&quot;http://www.cyberciti.biz/tips/reboot-or-halt-linux-system-in-emergency.html&quot; rel=&quot;nofollow&quot;&gt;link&lt;/a&gt; for more info.</description> <content:encoded><![CDATA[<p>Type the following to disable it:<br
/> <code>echo 'kernel.sysrq=0' &gt;&gt; /etc/sysctl.conf<br
/> sysctl -p</code></p><p>See this <a
href="http://www.cyberciti.biz/tips/reboot-or-halt-linux-system-in-emergency.html" rel="nofollow">link</a> for more info.</p> ]]></content:encoded> </item> <item><title>By: geoff_f</title><link>http://www.cyberciti.biz/tips/tips-to-protect-linux-servers-physical-console-access.html#comment-147901</link> <dc:creator>geoff_f</dc:creator> <pubDate>Mon, 30 Mar 2009 10:49:19 +0000</pubDate> <guid
isPermaLink="false">http://www.cyberciti.biz/tips/?p=4490#comment-147901</guid> <description>You can disable Ctrl-Alt-Del, but what about Alt-SysRq rseiub?</description> <content:encoded><![CDATA[<p>You can disable Ctrl-Alt-Del, but what about Alt-SysRq rseiub?</p> ]]></content:encoded> </item> <item><title>By: manju</title><link>http://www.cyberciti.biz/tips/tips-to-protect-linux-servers-physical-console-access.html#comment-147803</link> <dc:creator>manju</dc:creator> <pubDate>Mon, 23 Mar 2009 14:20:52 +0000</pubDate> <guid
isPermaLink="false">http://www.cyberciti.biz/tips/?p=4490#comment-147803</guid> <description>Thanks vivek</description> <content:encoded><![CDATA[<p>Thanks vivek</p> ]]></content:encoded> </item> <item><title>By: Vivek Gite</title><link>http://www.cyberciti.biz/tips/tips-to-protect-linux-servers-physical-console-access.html#comment-147799</link> <dc:creator>Vivek Gite</dc:creator> <pubDate>Mon, 23 Mar 2009 12:53:16 +0000</pubDate> <guid
isPermaLink="false">http://www.cyberciti.biz/tips/?p=4490#comment-147799</guid> <description>Syntax is as follows:
&lt;pre&gt;id:runlevels:action:process&lt;/pre&gt;
&lt;ul&gt;
&lt;li&gt;id -  a  unique  sequence  of  1-4 characters which identifies an entry in inittab &lt;/li&gt;
&lt;li&gt;S - the runlevels for which the specified action should be taken. Here S indicates single user mode.&lt;/li&gt;
&lt;li&gt;wait - The process will be started once when the specified runlevel is entered and init will wait for its termination.&lt;/li&gt;
&lt;li&gt;process - run /sbin/sulogin program when entered in S runlevel.&lt;/li&gt;
&lt;/ul&gt; </description> <content:encoded><![CDATA[<p>Syntax is as follows:</p><pre>id:runlevels:action:process</pre><ul><li>id &#8211;  a  unique  sequence  of  1-4 characters which identifies an entry in inittab</li><li>S &#8211; the runlevels for which the specified action should be taken. Here S indicates single user mode.</li><li>wait &#8211; The process will be started once when the specified runlevel is entered and init will wait for its termination.</li><li>process &#8211; run /sbin/sulogin program when entered in S runlevel.</li></ul> ]]></content:encoded> </item> <item><title>By: manju</title><link>http://www.cyberciti.biz/tips/tips-to-protect-linux-servers-physical-console-access.html#comment-147798</link> <dc:creator>manju</dc:creator> <pubDate>Mon, 23 Mar 2009 12:25:42 +0000</pubDate> <guid
isPermaLink="false">http://www.cyberciti.biz/tips/?p=4490#comment-147798</guid> <description>can any body explains the arguments in the line &quot;~~:S:wait:/sbin/sulogin&quot;, that means why we put ~~ and what is &quot;S&quot; stands for etc...</description> <content:encoded><![CDATA[<p>can any body explains the arguments in the line &#8220;~~:S:wait:/sbin/sulogin&#8221;, that means why we put ~~ and what is &#8220;S&#8221; stands for etc&#8230;</p> ]]></content:encoded> </item> <item><title>By: blackice</title><link>http://www.cyberciti.biz/tips/tips-to-protect-linux-servers-physical-console-access.html#comment-147786</link> <dc:creator>blackice</dc:creator> <pubDate>Sun, 22 Mar 2009 08:55:02 +0000</pubDate> <guid
isPermaLink="false">http://www.cyberciti.biz/tips/?p=4490#comment-147786</guid> <description>Really nice tips and highly professional how to ,  Enable Authentication for Single-User Mode was a good tip :) ..</description> <content:encoded><![CDATA[<p>Really nice tips and highly professional how to ,  Enable Authentication for Single-User Mode was a good tip :) ..</p> ]]></content:encoded> </item> <item><title>By: JFM</title><link>http://www.cyberciti.biz/tips/tips-to-protect-linux-servers-physical-console-access.html#comment-147767</link> <dc:creator>JFM</dc:creator> <pubDate>Fri, 20 Mar 2009 11:39:42 +0000</pubDate> <guid
isPermaLink="false">http://www.cyberciti.biz/tips/?p=4490#comment-147767</guid> <description>To SPM
In a passwordless Grub open the kernel line and add init=/bin/sh and boot.; That is all.  Now you are root.</description> <content:encoded><![CDATA[<p>To SPM</p><p>In a passwordless Grub open the kernel line and add init=/bin/sh and boot.; That is all.  Now you are root.</p> ]]></content:encoded> </item> <item><title>By: SPM</title><link>http://www.cyberciti.biz/tips/tips-to-protect-linux-servers-physical-console-access.html#comment-147756</link> <dc:creator>SPM</dc:creator> <pubDate>Thu, 19 Mar 2009 17:57:01 +0000</pubDate> <guid
isPermaLink="false">http://www.cyberciti.biz/tips/?p=4490#comment-147756</guid> <description>You forgot providing a case padlock. If the case isn&#039;t physically secure, everything else is for nought.
All an attacker needs is a screwdriver to open the case and reset the BIOS, boot a disaster recovery Linux distro off a CD or USB, mount the filesystem and voila - you can bypass all the other measures.
I an not too sure about the usefulness of the grub password. If you can bypass the BIOS, you can bypass grub, and if you have a bios password to protect against altering bios to allow booting off CD or USB, do you need a grub password?</description> <content:encoded><![CDATA[<p>You forgot providing a case padlock. If the case isn&#8217;t physically secure, everything else is for nought.</p><p>All an attacker needs is a screwdriver to open the case and reset the BIOS, boot a disaster recovery Linux distro off a CD or USB, mount the filesystem and voila &#8211; you can bypass all the other measures.</p><p>I an not too sure about the usefulness of the grub password. If you can bypass the BIOS, you can bypass grub, and if you have a bios password to protect against altering bios to allow booting off CD or USB, do you need a grub password?</p> ]]></content:encoded> </item> <item><title>By: Akshay</title><link>http://www.cyberciti.biz/tips/tips-to-protect-linux-servers-physical-console-access.html#comment-147656</link> <dc:creator>Akshay</dc:creator> <pubDate>Sat, 14 Mar 2009 09:44:57 +0000</pubDate> <guid
isPermaLink="false">http://www.cyberciti.biz/tips/?p=4490#comment-147656</guid> <description>Thanks for that tip..i only want to know how to stop booting into another medium..isnt there anything that can be done..</description> <content:encoded><![CDATA[<p>Thanks for that tip..i only want to know how to stop booting into another medium..isnt there anything that can be done..</p> ]]></content:encoded> </item> <item><title>By: Ulver</title><link>http://www.cyberciti.biz/tips/tips-to-protect-linux-servers-physical-console-access.html#comment-147644</link> <dc:creator>Ulver</dc:creator> <pubDate>Fri, 13 Mar 2009 13:01:12 +0000</pubDate> <guid
isPermaLink="false">http://www.cyberciti.biz/tips/?p=4490#comment-147644</guid> <description>interesting tips, specially advices related to interactive boot on rhel o similiar and single user booting autentication
Thanks for share those tips !</description> <content:encoded><![CDATA[<p>interesting tips, specially advices related to interactive boot on rhel o similiar and single user booting autentication</p><p> Thanks for share those tips !</p> ]]></content:encoded> </item> <item><title>By: mhernandez</title><link>http://www.cyberciti.biz/tips/tips-to-protect-linux-servers-physical-console-access.html#comment-147634</link> <dc:creator>mhernandez</dc:creator> <pubDate>Thu, 12 Mar 2009 21:24:07 +0000</pubDate> <guid
isPermaLink="false">http://www.cyberciti.biz/tips/?p=4490#comment-147634</guid> <description>Nice tip list: as you say, there&#039;s not much you can do if the physical security is violated but as they say it&#039;s always better being safe than sorry.
Thanks!</description> <content:encoded><![CDATA[<p>Nice tip list: as you say, there&#8217;s not much you can do if the physical security is violated but as they say it&#8217;s always better being safe than sorry.</p><p>Thanks!</p> ]]></content:encoded> </item> </channel> </rss>
