13 Sep
2016
13 Sep
'16
16:12
Le 13/09/2016 à 17:53, Bjoern Voigt a écrit :
As a result, if an attacker already knows the root password, but has no access to the OTP generating device,
? he can boot into single user /
rescue mode and there he can login with the known root password.
one can boot without any passwd with init=bash (or something similar, I say this from memory) and with rescue disk, root have no passwd but I'm not sure to understand your question :-( jdd -- To unsubscribe, e-mail: opensuse+unsubscribe@opensuse.org To contact the owner, e-mail: opensuse+owner@opensuse.org