Red Hat Bugzilla – Bug 8373
anyone allowed to shutdown
Last modified: 2008-05-01 11:37:53 EDT
Why does your log-in screen allow anyone to reboot or halt the machine?
Futhermore....when logged inas a user I can shut the machine down by
simply suppling the user password.
On servers, these two items should be reserved for root only.
If you have access to the console you have access to the power switch. Whcih
means that you can reboot.
So if you are a legit user of the machine then you already have those