Why is it possible to change the password of an admin user on linux?
Posted
by
enum
on Super User
See other posts from Super User
or by enum
Published on 2012-10-18T14:38:41Z
Indexed on
2012/10/18
23:05 UTC
Read the original article
Hit count: 130
A few days ago, a friend of mine, wanted to show me that he can use my linux even if I don't tell him my password.
He entered in GRUB, selected the recovery mode option. My first problem is that he already had access to my files (read only). He tried to do passwd but failed. Then he did some kind of remount (I guess that gave him write rights) and after that he was able to change my password.
Why is this possible? I personally see it a security issue. Where I work there are several people that use linux and neither of them have a BIOS password set or some other kind of security wall.
© Super User or respective owner