1 |
Oliver Schad wrote: |
2 |
> Am Samstag, 18. Februar 2006 01:48 schrieb mir Christian Limberg: |
3 |
> |
4 |
>> maybe you can emerge tools like chrootkit or rkhunter for checking |
5 |
>> your box for intruders. Clearly, it wouldn't help, if someone has |
6 |
>> 'bruteforced' your password, but if an intruder came throu a |
7 |
>> vunerable application and installed a rootkit or something like that, |
8 |
>> the tools might help you. |
9 |
>> |
10 |
> |
11 |
> No, you can't detect with those tools if your system is *not* |
12 |
> compromised. |
13 |
> |
14 |
> |
15 |
>> Furthermore it is highly recommended, that your root-password |
16 |
>> contains of a non-dictionay alpha-numeric (at least capitals, lower |
17 |
>> case letters and numbers) 8 character long phrase. |
18 |
>> |
19 |
> |
20 |
> And it it highly recommended to set up a new system from scratch. |
21 |
> Everything else is Russian roulette. |
22 |
> |
23 |
> Regards |
24 |
> Oli |
25 |
> |
26 |
There are a lot of good schemes for creating solid, memorable passwords. |
27 |
My favorite advice comes from the USAH (http://www.admin.com/). To |
28 |
paraphrase, come up with a nonsensical and slightly offensive (George |
29 |
Carlin's seven words are allowed: |
30 |
http://en.wikipedia.org/wiki/Seven_dirty_words) phrase of a half dozen |
31 |
or so words. Take the first two letters from each word. Then mix up the |
32 |
case and use numbers or symbols to replace certain letters occasionally. |
33 |
The result is a pretty solid password that you should be able to |
34 |
remember by remembering the silly phrase you started with. |
35 |
-- |
36 |
gentoo-security@g.o mailing list |