Results 1 to 3 of 3

Thread: security issues when using a LiveCD

  1. #1
    Junior Member
    Join Date
    Mar 2005
    Posts
    2

    security issues when using a LiveCD

    Hi there. I am wondering what security issues arise when using a LiveCD on a machine with an existing OS, in particular Windows. I understand that Knoppix can mount partitions in read-only mode. In such case, one may still save work to a Zip-disk, USB-key, etc. However, as regards access to authentication servers, (we're in a large campus which is predominately Windows (clients and servers)), network access, etc., does the use of a LiveCD (be it Linux, BSD, etc) impose any significant security threats to the existing infrastructure? Thanks in advance.

  2. #2
    Junior Member registered user
    Join Date
    Mar 2005
    Posts
    29
    As long as you allow your users to boot a LiveCD, anything is no longer secure. Don't even think M$ could be intact, there are LiveCDs such as AUSTRUMI built with capabilities to blank the administrator's password even the latest patches or service packs were applied.

  3. #3
    Senior Member registered user
    Join Date
    Oct 2004
    Location
    london town
    Posts
    220
    does a live cd pose as any threat to your windows network do you mean?

    in some ways yes but only if someone is able to boot up a windows machine using a linux live cd and this is only a threat because people can copy what ever data from the hard drive. such as encrypted password files. other then that i dont belive it will pose any threat. unless of course your windows boxes are 1 not configured correctly such as weak passwords(blank passwds) outdated servers (iis netbios etc)but this would be no differnt if someone was using windows and wanted to attack your network. they will be asked for a password when trying to access windows shares

    a machine running a live linux cd is unlikly to get compramised. but is possible the servers are not always upto date and local privilege escalation is not that much of a problem. for instance if you was to allow someone to log in using the knoppix account. they could with ease jump to root with sudo su or just su as it doesnt ask for a password from what i remember.

    so there are certain threats but you just have to treat them like most normal threats and take steps against them. such as passwording the bios so people cant boot live cds. disabling guest accounts on windows machines. making sure all accounts have passwords(even though ms alot of the time doesnt allow people to sign on with blank passwords)making sure the computers are upto date.

Similar Threads

  1. Two Issues - Zombies and Security...
    By Cuddles in forum General Support
    Replies: 4
    Last Post: 09-13-2004, 08:11 AM
  2. Hdd Security
    By NetKatz in forum Hdd Install / Debian / Apt
    Replies: 2
    Last Post: 05-02-2004, 02:38 PM
  3. Security
    By pierrevn in forum General Support
    Replies: 5
    Last Post: 12-12-2003, 07:34 AM
  4. Security and apt-get
    By Edix in forum Hdd Install / Debian / Apt
    Replies: 1
    Last Post: 11-10-2003, 08:20 PM
  5. security
    By kipizit in forum General Support
    Replies: 1
    Last Post: 11-07-2003, 03:08 AM

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •  


Dell Poweredge R630 2x Xeon E5-2680 v4 2.4ghz 28-Cores / 128gb / H330 / 2x 1TB picture

Dell Poweredge R630 2x Xeon E5-2680 v4 2.4ghz 28-Cores / 128gb / H330 / 2x 1TB

$334.99



Dell PowerEdge R730 2x E5-2699V3 2.3Ghz 36 Core 128GB RAM H730 X520-I350 2x750W picture

Dell PowerEdge R730 2x E5-2699V3 2.3Ghz 36 Core 128GB RAM H730 X520-I350 2x750W

$329.99



Dell PowerEdge R630 Server 2x E5-2640v3 2.60Ghz 16-Core 64GB H330 picture

Dell PowerEdge R630 Server 2x E5-2640v3 2.60Ghz 16-Core 64GB H330

$182.65



Dell Poweredge R630 Server 2x E5-2620 V4 =16 Cores | S130 | 32GB RAM | 2x trays picture

Dell Poweredge R630 Server 2x E5-2620 V4 =16 Cores | S130 | 32GB RAM | 2x trays

$159.99



Dell PowerEdge R630 Server 2x E5-2680 V4 = 28 Cores S130 32GB RAM NEW 480GB SSD picture

Dell PowerEdge R630 Server 2x E5-2680 V4 = 28 Cores S130 32GB RAM NEW 480GB SSD

$197.99



DELL R630 SERVER 8 x 2.5'' 2X E5-2680V4 32GB RAM IDRAC ENT & NDC 2X 495W PSU picture

DELL R630 SERVER 8 x 2.5'' 2X E5-2680V4 32GB RAM IDRAC ENT & NDC 2X 495W PSU

$184.95



Dell PowerEdge R720xd 26HDD 300gb  2.5-inch E5-2697  X 2CPU 384RAM 7.2 Tb HDD  picture

Dell PowerEdge R720xd 26HDD 300gb 2.5-inch E5-2697 X 2CPU 384RAM 7.2 Tb HDD 

$180.00



Dell Poweredge R730xd 12 Bay LFF 2x SFF  2x E5-2680v3 2.5ghz H730p No Ram No HDD picture

Dell Poweredge R730xd 12 Bay LFF 2x SFF 2x E5-2680v3 2.5ghz H730p No Ram No HDD

$219.99



DELL PowerEdge R630 8SFF Server 2x E5-2680v3 2.5GHz =24 Cores 128GB H730 4xRJ45 picture

DELL PowerEdge R630 8SFF Server 2x E5-2680v3 2.5GHz =24 Cores 128GB H730 4xRJ45

$338.00



DELL PowerEdge R730 Server 2x E5-2698v4 2.2GHz =40 Cores 128GB H730 4xRJ45 picture

DELL PowerEdge R730 Server 2x E5-2698v4 2.2GHz =40 Cores 128GB H730 4xRJ45

$601.00