Why is it possible to change the password of an admin user on linux?

Posted by enum on Super User See other posts from Super User or by enum
Published on 2012-10-18T14:38:41Z Indexed on 2012/10/18 23:05 UTC
Read the original article Hit count: 135

Filed under:
|
|
|
|

A few days ago, a friend of mine, wanted to show me that he can use my linux even if I don't tell him my password.

He entered in GRUB, selected the recovery mode option. My first problem is that he already had access to my files (read only). He tried to do passwd but failed. Then he did some kind of remount (I guess that gave him write rights) and after that he was able to change my password.

Why is this possible? I personally see it a security issue. Where I work there are several people that use linux and neither of them have a BIOS password set or some other kind of security wall.

© Super User or respective owner

Related posts about linux

Related posts about security