SYSTEM WARNING: 'date_default_timezone_get(): It is not safe to rely on the system's timezone settings. You are *required* to use the date.timezone setting or the date_default_timezone_set() function. In case you used any of those methods and you are still getting this warning, you most likely misspelled the timezone identifier. We selected the timezone 'UTC' for now, but please set date.timezone to select your timezone.' in '/usr/share/mantis/www/core.php' line 264

0000236: endian-firewall can be rebooted from console without password - MantisBT Endian Bugtracker
Endian Issue Tracker





Please see now our new Bugtracker system: JIRA








View Issue Details Jump to Notes ] Issue History ] Print ]
IDProjectCategoryView StatusDate SubmittedLast Update
0000236Endian FirewallSecuritypublic2007-08-06 15:022007-12-31 19:15
Reporterchhaas 
Assigned Topeter-endian 
PrioritynormalSeveritymajorReproducibilityalways
StatusclosedResolutionfixed 
PlatformOSOS Version
Product Version2.1 
Target VersionFixed in Version2.2-beta2 
Summary0000236: endian-firewall can be rebooted from console without password
Descriptionthe efw can be rebooted from the console just by pressing "2" and the "y" key.

A reboot should only be possible after password-authentication.

Of course, console-access should be prohibited by the admin, but reboot by a password ;-)

Cheers
Christoph.
TagsNo tags attached.
Attached Files

- Relationships

-  Notes
(0000567)
peter-endian (administrator)
2007-10-27 20:30

This possibility has been removed within version 2.2 *for now*, as well as password reset.

However it's no good solution either, since now there is no possibility to reset the password if a user forgot it.

On the other hand, if someone was able to connect to the console in order to start the reboot process it also has the possibility to reboot just by stripping the power cord.

- Issue History
Date Modified Username Field Change
2007-08-06 15:02 chhaas New Issue
2007-10-27 20:30 peter-endian Status new => resolved
2007-10-27 20:30 peter-endian Fixed in Version => 2.2
2007-10-27 20:30 peter-endian Resolution open => fixed
2007-10-27 20:30 peter-endian Assigned To => peter-endian
2007-10-27 20:30 peter-endian Note Added: 0000567
2007-12-31 19:15 raphael-endian Fixed in Version 2.2-beta1 => 2.2-beta2
2007-12-31 19:15 raphael-endian Status resolved => closed

Copyright © 2005-2008 Endian, SRL. All rights reserved.


Copyright © 2000 - 2012 MantisBT Group
Powered by Mantis Bugtracker