63 lines
4.0 KiB
HTML
63 lines
4.0 KiB
HTML
<!DOCTYPE HTML PUBLIC "-//W3O//DTD W3 HTML 2.0//EN">
|
|
<!Converted with LaTeX2HTML 95.1 (Fri Jan 20 1995) by Nikos Drakos (nikos@cbl.leeds.ac.uk), CBLU, University of Leeds >
|
|
<HEAD>
|
|
<TITLE>4.1.2 Abusing the system</TITLE>
|
|
</HEAD>
|
|
<BODY>
|
|
<meta name="description" value="4.1.2 Abusing the system">
|
|
<meta name="keywords" value="gs">
|
|
<meta name="resource-type" value="document">
|
|
<meta name="distribution" value="global">
|
|
<P>
|
|
<BR> <HR><A NAME=tex2html3790 HREF="node159.html"><IMG ALIGN=BOTTOM ALT="next" SRC="next_motif.gif"></A> <A NAME=tex2html3788 HREF="node156.html"><IMG ALIGN=BOTTOM ALT="up" SRC="up_motif.gif"></A> <A NAME=tex2html3782 HREF="node157.html"><IMG ALIGN=BOTTOM ALT="previous" SRC="previous_motif.gif"></A> <A NAME=tex2html3792 HREF="node1.html"><IMG ALIGN=BOTTOM ALT="contents" SRC="contents_motif.gif"></A> <A NAME=tex2html3793 HREF="node250.html"><IMG ALIGN=BOTTOM ALT="index" SRC="index_motif.gif"></A> <BR>
|
|
<B> Next:</B> <A NAME=tex2html3791 HREF="node159.html">4.1.3 Dealing with users</A>
|
|
<B>Up:</B> <A NAME=tex2html3789 HREF="node156.html">4.1 About RootHats, </A>
|
|
<B> Previous:</B> <A NAME=tex2html3783 HREF="node157.html">4.1.1 The root account</A>
|
|
<BR> <HR> <P>
|
|
<H2><A NAME=SECTION00612000000000000000>4.1.2 Abusing the system</A></H2>
|
|
<P>
|
|
<A NAME=4211> </A>
|
|
Along with the feeling of power comes the tendency to do harm. This
|
|
is one of the grey areas of UNIX system administration, but everyone
|
|
goes through it at some point in time. Most users of UNIX systems never
|
|
have the ability to wield this power---on university and business UNIX
|
|
systems, only the highly-paid and highly-qualified system administrators ever
|
|
login as <tt>root</tt>. In fact, at many such institutions, the <tt>root</tt>
|
|
password is a highly guarded secret: it is treated as the Holy Grail of the
|
|
institution. A large amount of hubbub is made about logging in as <tt>root</tt>;
|
|
it is portrayed as a wise and fearsome power, given only to an exclusive
|
|
cabal.
|
|
<P>
|
|
This kind of attitude towards the <tt>root</tt> account is, quite simply, the
|
|
kind of thing which breeds malice and contempt. Because <tt>root</tt> is so
|
|
fluffed-up, when some users have their first opportunity to login as
|
|
<tt>root</tt> (either on a Linux system or elsewhere), the tendency is to
|
|
use <tt>root</tt>'s privileges in a harmful manner. I have known so-called
|
|
``system administrators'' who read other user's mail, delete user's files
|
|
without warning, and generally behave like children when given such a
|
|
powerful ``toy''.
|
|
<P>
|
|
Because <tt>root</tt> has such privilege on the system, it takes a
|
|
certain amount of maturity and self-control to use the account as it
|
|
was intended---to
|
|
run the system. There is an unspoken code of honor which exists between
|
|
the system administrator and the users on the system. How would you feel
|
|
if your system administrator was reading your e-mail or looking over your
|
|
files? There is still no strong legal precedent for electronic privacy on
|
|
time-sharing computer systems. On UNIX systems, the <tt>root</tt> user has
|
|
the ability to forego all security and privacy mechanisms on the system.
|
|
It is important that the system administrator develop a trusting relationship
|
|
with the users on the system. I can't stress that enough.
|
|
<P>
|
|
<BR> <HR><A NAME=tex2html3790 HREF="node159.html"><IMG ALIGN=BOTTOM ALT="next" SRC="next_motif.gif"></A> <A NAME=tex2html3788 HREF="node156.html"><IMG ALIGN=BOTTOM ALT="up" SRC="up_motif.gif"></A> <A NAME=tex2html3782 HREF="node157.html"><IMG ALIGN=BOTTOM ALT="previous" SRC="previous_motif.gif"></A> <A NAME=tex2html3792 HREF="node1.html"><IMG ALIGN=BOTTOM ALT="contents" SRC="contents_motif.gif"></A> <A NAME=tex2html3793 HREF="node250.html"><IMG ALIGN=BOTTOM ALT="index" SRC="index_motif.gif"></A> <BR>
|
|
<B> Next:</B> <A NAME=tex2html3791 HREF="node159.html">4.1.3 Dealing with users</A>
|
|
<B>Up:</B> <A NAME=tex2html3789 HREF="node156.html">4.1 About RootHats, </A>
|
|
<B> Previous:</B> <A NAME=tex2html3783 HREF="node157.html">4.1.1 The root account</A>
|
|
<BR> <HR> <P>
|
|
<BR> <HR>
|
|
<P><ADDRESS>
|
|
<I>Matt Welsh <BR>
|
|
mdw@sunsite.unc.edu</I>
|
|
</ADDRESS>
|
|
</BODY>
|