Skip site navigation (1)Skip section navigation (2)
Date:      Sat, 28 Jun 1997 00:48:12 -0700 (PDT)
From:      Tom Samplonius <tom@sdf.com>
To:        Simon Shapiro <Shimon@i-Connect.Net>
Cc:        Bruce Evans <bde@zeta.org.au>, mburgett@cmnsens.zoom.com, freebsd-hackers@freebsd.org
Subject:   Re: com console, and h/w flow control...
Message-ID:  <Pine.BSF.3.95q.970628004030.8640B-100000@misery.sdf.com>
In-Reply-To: <XFMail.970628001456.Shimon@i-Connect.Net>

next in thread | previous in thread | raw e-mail | index | archive | help

On Sat, 28 Jun 1997, Simon Shapiro wrote:

> One logs in on the serial console from a modem (or terminal server),
> becomes root and the serial connection drops (noisy modem line, etc.).  
> 
> At this point ANYONE who dials-in is ROOT!

  This is not really what the COM console was designed for anyhow.  Don't
use a modem on it, ever.

  Not only could modem users grab root, as above, if they happen to be on
when the system is booting, they could simply boot single user.  Remember,
the COM console features give you CONSOLE access, and such access should
not be taken lightly!

  So DON'T use a modem on a COM console.  Configure a regular serial port
instead.

  If you need to use the console remotely, and want to use COM console for
this, use another FreeBSD box with a null modem cable to the console port.
Or, you could use a terminal server for this (this is what I do, mainly
because I have a two spare Portmasters).

Tom





Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?Pine.BSF.3.95q.970628004030.8640B-100000>