
| Anonymous | Login | Signup for a new account | 2010-09-04 01:39 CEST |
| Main | My View | View Issues | Change Log | Roadmap | Docs |
| Viewing Issue Simple Details [ Jump to Notes ] | [ View Advanced ] [ Issue History ] [ Print ] | |||||||||||
| ID | Category | Severity | Reproducibility | Date Submitted | Last Update | |||||||
| 0000308 | [Endian Firewall] Security | feature | always | 2007-11-09 22:33 | 2010-01-21 19:28 | |||||||
| Reporter | rainy | View Status | public | |||||||||
| Assigned To | ||||||||||||
| Priority | none | Resolution | open | |||||||||
| Status | new | Product Version | 2.2-beta1 | |||||||||
| Summary | 0000308: auto login allows reboot and reset to factory-default | |||||||||||
| Description |
After booting the system, I found out that there is an auto login running which gives a menu at the console: 0 shell 1 reset to factory default 2 reboot I had to find out, that option 0 (shell) requires a user and login password, however options 1 and 2 don't even ask for a password, just ask for confirmation by entering a 'y'. I don't think that is is a real good idea for a security system. Local users might cause a denial of service or even take control at the firewall by resetting the system to factory default and then take control over it by setting a new configuration! Please be aware of this serious issue! |
|||||||||||
| Additional Information | ||||||||||||
| Tags | No tags attached. | |||||||||||
| Attached Files | ||||||||||||
|
|
||||||||||||
Relationships |
|||||||||||
|
|||||||||||
| Mantis [^] Copyright © 2000 - 2008 Mantis Group |