[plug] Did something dumb.

shayne - sYra shayne at syra.com.au
Thu Jul 5 10:46:41 WST 2007


Ouch.

Well, you could always go and find a root exploit and 'sploit your own 
box. I did that once on a server I maintained where I screwed up sudo (I 
removed root before verifying sudo worked. Doh).

This was all before I learned the whole boot/mount/chroot and 
init=/bin/bash tricks.

Of course if your kernel is up to date, your kinda hosed.

Brad Campbell wrote:
> G'day all.
> 
> I've got a remote box (I have physical access to it, just not for a few 
> days).
> It's an Ubuntu server install, so by default it has no root password. 
> Can't su, can't ssh in as root.
> 
> I changed the hostname. Now the host name is not listed in /etc/hosts or 
> resolvable via dns.
> 
> I can not longer use sudo and believe I have have no way of getting root 
> access on the box short of a power cycle and init=/bin/bash
> 
> brad at dev-001:~$ sudo -s
> sudo: unable to lookup dev-001 via gethostbyname()
> brad at dev-001:~$ sudo -s
> 
> Bugger huh.. I've not really kept the box up to date so I've been 
> browsing for exploits for anything I've got installed, but not found 
> anything. I'm pretty resigned now to wait until I can get physical 
> access but just for chuckles I thought I'd let you all know what I did 
> and how I did it to serve as a warning.
> 
> Brad



More information about the plug mailing list