[Asterisk-Users] Re: asterisk@home scary log

Rich Adamson radamson at routers.com
Thu Feb 10 12:37:55 MST 2005


> >> I'll call bullshit on that. I know for a fact that Debian does NOT 
> >> allow root logins except from console. Hell Debian isn't allowing 
> >> root logins
> >> from X anymore due to the likely hood for you to try and use root for 
> >> more than administration.
> >
> >
> > I'm sure that's true nowadays.  I haven't played with Debian in years, 
> > or slackware, or FreeBSD.  All the others on the list I have messed 
> > around with (fairly) recently, and they allow root logins via ssh by 
> > default.
> >
> 
> I'm glad somebody brought this up.  I just checked my Mandrake 9, 9.2, 
> 10 and 10.1 servers.  In the sshd_config all servers were set, by 
> default, to PermitRootLogin=yes.
> 
> I've since changed them.

Are you absolutely sure that root access is the only problem?

What about all the other accounts that get installed by default?

I'd suggest looking at those parameters again and allow only those
userid's that you are comfortable with, and by default that
disables all other system accounts.





More information about the asterisk-users mailing list