From owner-freebsd-questions@FreeBSD.ORG Thu Jan 11 14:49:00 2007 Return-Path: X-Original-To: freebsd-questions@FreeBSD.ORG Delivered-To: freebsd-questions@FreeBSD.ORG Received: from mx1.freebsd.org (mx1.freebsd.org [69.147.83.52]) by hub.freebsd.org (Postfix) with ESMTP id EA1F716A494 for ; Thu, 11 Jan 2007 14:49:00 +0000 (UTC) (envelope-from olli@lurza.secnetix.de) Received: from lurza.secnetix.de (lurza.secnetix.de [83.120.8.8]) by mx1.freebsd.org (Postfix) with ESMTP id 75DDB13C469 for ; Thu, 11 Jan 2007 14:49:00 +0000 (UTC) (envelope-from olli@lurza.secnetix.de) Received: from lurza.secnetix.de (juzmjk@localhost [127.0.0.1]) by lurza.secnetix.de (8.13.4/8.13.4) with ESMTP id l0BEmraC099464; Thu, 11 Jan 2007 15:48:59 +0100 (CET) (envelope-from oliver.fromme@secnetix.de) Received: (from olli@localhost) by lurza.secnetix.de (8.13.4/8.13.1/Submit) id l0BEmrR1099463; Thu, 11 Jan 2007 15:48:53 +0100 (CET) (envelope-from olli) Date: Thu, 11 Jan 2007 15:48:53 +0100 (CET) Message-Id: <200701111448.l0BEmrR1099463@lurza.secnetix.de> From: Oliver Fromme To: freebsd-questions@FreeBSD.ORG, nathan@vidican.com In-Reply-To: <45A6412C.308@vidican.com> X-Newsgroups: list.freebsd-questions User-Agent: tin/1.8.2-20060425 ("Shillay") (UNIX) (FreeBSD/4.11-STABLE (i386)) X-Greylist: Sender IP whitelisted, not delayed by milter-greylist-2.1.2 (lurza.secnetix.de [127.0.0.1]); Thu, 11 Jan 2007 15:48:59 +0100 (CET) Cc: Subject: Re: How dangerous a Standard User could be to a FreeBSD box? X-BeenThere: freebsd-questions@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list Reply-To: freebsd-questions@FreeBSD.ORG, nathan@vidican.com List-Id: User questions List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Thu, 11 Jan 2007 14:49:01 -0000 Nathan Vidican wrote: > James Long wrote: > > Yeah, and even a user with no account or password, a screwdriver, and > > a Mountain Dew. > > Gotcha all beat, screw the 'standard user' issue... I had a client call > me once cause the office cat peed onto/into the server; no technical > expertise required whatsoever, no password, no re-wiring of network, > heck no opposable digits even or anything else for that matter, yet it > still managed to kill the server ;) Reminds me of this one ... http://www.secnetix.de/~olli/fun/bruteforce-cat.jpg Best regards Oliver -- Oliver Fromme, secnetix GmbH & Co. KG, Marktplatz 29, 85567 Grafing Dienstleistungen mit Schwerpunkt FreeBSD: http://www.secnetix.de/bsd Any opinions expressed in this message may be personal to the author and may not necessarily reflect the opinions of secnetix in any way. "If Java had true garbage collection, most programs would delete themselves upon execution." -- Robert Sewell