pen-test
[Top] [All Lists]

Re: Gain root access on linux servers with physical access

Subject: Re: Gain root access on linux servers with physical access
From: Patrick <flymooney@gmail.com>
Date: Sat, 16 Dec 2006 19:21:08 -0500
Cc: pen-test@securityfocus.com
Delivered-to: sp-com-lists@consult.net
Delivered-to: pentest-list2@consult.net
Delivered-to: mailing list pen-test@securityfocus.com
Delivered-to: moderator for pen-test@securityfocus.com
Domainkey-signature: a=rsa-sha1; q=dns; c=nofws; s=beta; d=gmail.com; h=received:message-id:date:from:organization:user-agent:mime-version:cc:subject:references:in-reply-to:content-type:content-transfer-encoding; b=MTGQ/HbBGF1OAC2Wdo8cLrMLD0AKA0r3G6sGxC2NhHxQfWEfoyqN9hmzIccv3nirXYjFRPFEgFtijnOvAGSdsHzoeTXBsZ8WbC9HN1L8JItZetj0rbfvNPHwXVx5faf/GXjqRY4loytKEe9zEsy3WneDMP62Sl7kiVyuKT0IROc=
In-reply-to: <20061214182715.2903.qmail@securityfocus.com>
List-help: <mailto:pen-test-help@securityfocus.com>
List-id: <pen-test.list-id.securityfocus.com>
List-post: <mailto:pen-test@securityfocus.com>
List-subscribe: <mailto:pen-test-subscribe@securityfocus.com>
List-unsubscribe: <mailto:pen-test-unsubscribe@securityfocus.com>
Mailing-list: contact pen-test-help@securityfocus.com; run by ezmlm
Organization: Complete Office Installations, Inc.
References: <20061214182715.2903.qmail@securityfocus.com>
Resent-date: Sat, 16 Dec 2006 16:34:03 -0700 (MST)
Resent-from: pen-test-return-1078483236@securityfocus.com
Resent-message-id: <20061216233403.CF0FB2371A2@outgoing3.securityfocus.com>
Resent-sender: listbounce@securityfocus.com
Sender: listbounce@securityfocus.com
User-agent: Thunderbird 1.5.0.8 (X11/20061107)
spammailme@gmail.com wrote:
All -

I was wondering ideas on how to gain control of linux boxes with physical access to them in the hosting facility.
The owner has code on them yet never bothered monitoring or gaining root access 
and her developers are blackmailing her. She has access the the hosting 
facility and the servers and backup staff yet needs to regain control of the 
servers.

If she has physical access, then she does not need anything else (other than a competent Linux person).



------------------------------------------------------------------------
This List Sponsored by: Cenzic

Need to secure your web apps?
Cenzic Hailstorm finds vulnerabilities fast.
Click the link to buy it, try it or download Hailstorm for FREE.
http://www.cenzic.com/products_services/download_hailstorm.php?camp=701600000008bOW
------------------------------------------------------------------------


<Prev in Thread] Current Thread [Next in Thread>