[nas-2000] Re: firmware: 2.3.2.IB.2.RS.1 / ssh-server plugin ...

  • From: "flipstar@xxxxxxx" <flipstar@xxxxxxx>
  • To: nas-2000@xxxxxxxxxxxxx
  • Date: Mon, 29 Oct 2007 21:38:49 +0100

Hey Oliver,

Oliver Brinzing schrieb:
> Hi Flip,
> are there any plans to fix the problem ?

I would say right person wrong list :-)

I would not say its a security issue because:

- its optional
- you can turn the ssh-server off

What stops you from adding a sed onliner to the init - script
that changes the root pw to the value you want?


>> there is a security problem using the ssh-server plugin:
>> root password is not stored on disk, so every time
>> one reboots, the default password should be changed ...
> Oliver

Other related posts: