Activities

November 2009
M T W T F S S
« Oct   Dec »
 1
2345678
9101112131415
16171819202122
23242526272829
30  

Webmin – How to get root privillages

Recently one of the clients provides me a a webmin admin user accounts to host a website which subversion enabled on it.

Also I need to create a domain for hosting and email account. So I prefer to install ‘Virtualin’ on the server. My requirement is each of the sites must have using subversion. So must a ssh access and I haven’t provided root access even client hasn’t any idea about it.

Solution,

1. I created 2 user accounts. A normal user for ssh login becaue ssh root access is disabled. The second one is root privileged user.
2. During the second user creation time using webmin–>System users, I set the user id to ‘0’ and choose the group to ‘root’. Then set a strong password.

How hacks worked.

1. First I login with a normal user account and switch to root privileged user by providing password.

[user@server]$ su -superuser

#
I got root shell mean I can do anything on the server.

2. I have reset the root password and deleted the super user which i created before after exiting from the ‘super user’ shell.

3. Updated root is send to clients as well 🙂

Leave a Reply

You can use these HTML tags

<a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <s> <strike> <strong>