ulisses1478 Posted October 9, 2019 Share Posted October 9, 2019 My brother picked up my unraid pendrive trying to steal my password. Have any possible way that he can get access to ssh/gui or my files in any way without my permission? if there is. How? Quote Link to comment
BRiT Posted October 9, 2019 Share Posted October 9, 2019 Anyone with physical access to the USB drive and the array system can get access to files that are not encrypted. They can wipe out the password fields entirely on the flash drive from a different system, insert the modified flash drive into the unraid system and turn it on. After boot up, they will have the system without passwords. The way to protect against that is using drive encryption with a passphrase only you know that is not stored on anything they have physical access to. However, I am unable to answer the question if your brother is smart enough to do this. Quote Link to comment
Frank1940 Posted October 9, 2019 Share Posted October 9, 2019 (edited) One way to help is to install the Fix Common Problems plugin. That plugin have a setting for the maximum number of invalid login attempts in a day. Then change your password to one that is at least 8 characters long and something difficult to guess since it is your brother. You also need to physically secure your server which may be much more difficult. Make sure that you have setup the certificate on your server so that you are using https. Edited October 9, 2019 by Frank1940 Quote Link to comment
ulisses1478 Posted October 13, 2019 Author Share Posted October 13, 2019 On 10/9/2019 at 10:21 AM, BRiT said: Anyone with physical access to the USB drive and the array system can get access to files that are not encrypted. They can wipe out the password fields entirely on the flash drive from a different system, insert the modified flash drive into the unraid system and turn it on. After boot up, they will have the system without passwords. The way to protect against that is using drive encryption with a passphrase only you know that is not stored on anything they have physical access to. However, I am unable to answer the question if your brother is smart enough to do this. He is smart , but I know when he unplug the flash drive out. after reseting the pass he has anyway to get access to the server? Quote Link to comment
Recommended Posts
Join the conversation
You can post now and register later. If you have an account, sign in now to post with your account.
Note: Your post will require moderator approval before it will be visible.