Тёмный

Set & Remove GRUB Password in RHEL 7/8 Or CentOS 7/8 | Break GRUB Password without Root Password 

Nehra Classes
Подписаться 46 тыс.
Просмотров 10 тыс.
50% 1

Set & Remove GRUB2 password in RHEL 7/8:
--------------------------------------------------
Why should a Linux boot loader have password protection?
The following are the primary reasons for password protecting a Linux boot loader:
1. Preventing Access to Single User Mode - If an attacker can boot into single user mode, he becomes the root user.
2. Preventing Access to the GRUB Console - If the machine uses GRUB as its boot loader, an attacker can use the GRUB editor interface to change its configuration or to gather information using the cat command.
3. Preventing Access to Non-Secure Operating Systems - If it is a dual-boot system, an attacker can select at boot time an operating system, such as DOS, which ignores access controls and file permissions.
Password protecting GRUB2:
Follow the steps below to password protect GRUB2 in RHEL 7.
1. Remove -unrestricted from the main CLASS= declaration in /etc/grub.d/10_linux file.
This can be done by using sed to replace the
sed -i "/^CLASS=/s/ --unrestricted//" /etc/grub.d/10_linux
2. If a user hasn’t already been configured, use grub2-setpassword to set a password for the root user :
grub2-setpassword
This creates a file /boot/grub2/user.cfg if not already present, which contains the hashed GRUB bootloader password. This utility only supports configurations where there is a single root user.
Example /boot/grub2/user.cfg file :
cat /boot/grub2/user.cfg
3. Recreate the grub config with grub2-mkconfig :
grub2-mkconfig -o /boot/grub2/grub.cfg
Generating grub configuration file ...
Found linux image: /boot/vmlinuz-3.10.0-327.el7.x86_64
Found initrd image: /boot/initramfs-3.10.0-327.el7.x86_64.img
Found linux image: /boot/vmlinuz-0-rescue-f9725b0c842348ce9e0bc81968cf7181
Found initrd image: /boot/initramfs-0-rescue-f9725b0c842348ce9e0bc81968cf7181.img
done
4. Reboot the server and verify.
shutdown -r now
Note that all defined grub menu entries will now require entering user & password each time at boot; henceforth, the system will not boot any kernel without direct user intervention from the console. When prompted for user, enter “root”. When prompted for password, enter whatever was passed to the grub2-setpassword command :
=========================
Remove password protection
To remove the password protection we can add the -unrestricted text in the main CLASS= declaration in /etc/grub.d/10_linux file again. Another way is to remove the /boot/grub2/user.cfg file which stores the hashed GRUB bootloader password.
rm -f /boot/grub2/user.cfg
(Credits: www.thegeekdiary.com/centos-r...)
==============================
Break/Remove the forgotten GRUB2 Password: (in case you don't know the root password)
---
If you don't know the GRUB password you can't easily reset the forgotten root password. So to reset the root password or remove the GRUB password in such scenario you need to boot up your server with iso image.
1. Boot with ISO image.
2. Select troubleshooting option.
3. From Troubleshooting options select Rescue a CentOS/RedHat Linux system option.
4. Now select the first option which mounts the installed Linux in /mnt/sysimage directory.
5. Now run following commands
#chroot /mnt/sysimage
#ls
6. Open /etc/grub2.cfg file in vi editor and comment user credential lines (username, export & password lines as shown in video):
vim /etc/grub2.cfg
Exit and Reboot again with HDD.
You are done.
==============================================
Thanks for watching the video. Please like our videos, share with your friends and feel free to ask anything, post your queries in comments section. We will feel glad to answer your question. And don't forget to subscribe the channel.
==================================================
Configure Apache Tomcat in Linux (RHEL/CentOS):
• How to install and Con...
DNS Configuration:
• Domain Name Server (DN...
Linux Fundamentals (Linux Basics) Session -1:
• Learn Linux Fundamenta...
===================================================
Contact Us:
To Follow Vikas Nehra's Twitter Handle:👇
bit.ly/VikasNehraTwitterHandle
For Registration:👇
bit.ly/NehraClassesRegForm
To Follow Our Twitter Handle:👇
bit.ly/NehraClassesTwiiterHandle
To Visit Our Facebook Page:👇
nehraclasses
To Follow Nehra Classes on Instagram:👇
/ nehraclasses
To Our Visit Our Webpage:👇
bit.ly/NehraClassesWebpage
Join Us on Telegram App: 👇
t.me/NehraClasses
WhatsApp Us: 👇
bit.ly/2Kpqp5z
Email Us:👇
Email: nehraclasses@gmail.com
============================
©COPYRIGHT. ALL RIGHTS RESERVED
#NehraClasses #LinuxTraining #ResetGrubPassword

Наука

Опубликовано:

 

10 мар 2020

Поделиться:

Ссылка:

Скачать:

Готовим ссылку...

Добавить в:

Мой плейлист
Посмотреть позже
Комментарии : 12   
@ravisoni7403
@ravisoni7403 3 года назад
I can easily understood what ever you explained becoz your teaching style absolutely clear Sir thanks for video.... And create more videos on troubleshooting...
@NehraClasses
@NehraClasses 3 года назад
Sure, thanks a lot
@Ray_TambaBudol_Marcos
@Ray_TambaBudol_Marcos Год назад
Amazing stuff bro, It may be different from CentOS7 but the concept is the same. you earn a new sub here.
@NehraClasses
@NehraClasses Год назад
Thanks for the sub!
@architsaki
@architsaki 2 года назад
Thanks Properly explained
@NehraClasses
@NehraClasses 2 года назад
You are welcome
@wymanchoo165
@wymanchoo165 2 года назад
What is the bind-key to save after we did the comment part of the grub2.cfg file?
@NehraClasses
@NehraClasses 2 года назад
Please contact us in telegram
@harshal_joshi
@harshal_joshi 10 месяцев назад
Thanks 👍
@zonglinchen3184
@zonglinchen3184 3 года назад
Where can I find an ISO image?
@NehraClasses
@NehraClasses 3 года назад
Download it from internet
@xaviont5673
@xaviont5673 7 месяцев назад
@@NehraClasses can u send me a link?
Далее
Alisha Lehmann joins Juventus Women 🤍🖤
00:16
Просмотров 3,8 млн
Breaking Root Password - RHEL 8
9:29
Просмотров 17 тыс.
How To Reset A Forgotten Password On Linux
13:04
Просмотров 18 тыс.
Reset Root Password - RHCSA v9 Review
10:02
Просмотров 4,5 тыс.
UBUNTU Using GRUB2 passwords
10:10
Просмотров 11 тыс.
Треш ПК за 420 000 рублей
0:59
Просмотров 87 тыс.
Здесь упор в процессор
18:02
Просмотров 239 тыс.
Так ли Хорош Founders Edition RTX 4080 ?
13:00