And what if the filesystem is encrypted?


Mount it the usual way for encrypted systems. I dont use it so i cant tell you how. The actual filesystem isnt relevant. As long as you can
access it ok. Just mount it rw and chroot into it.

But if the FS is encrypted with the root-PW
you`ve got _real_ trouble.

Correct me if I'm wrong but I'd say "In that case you are cooked!!"

Not that i know much of encrypted FS's, but id say you are pretty lost by
then. Unless you can brutecrack the encryption with some forensics

Start looking for post-it notes near the console....


LOL! Well unfortunately that IS a relevant observation...
(Been there, done that, trashed the user badly for compromising the security)
But all jokes aside.
If you DON'T know the password for the encryption, i think you are lost...

Well, that's the idea of encryption, isn't it? There might however be a chance to find the encryption key on the swap partition. I haven't looked at the code if it is really impossible that the relevant pages get swapped out.

But, just to reiterate what has been said earlier: if the root partition is not encrypted, you can always boot with init=/bin/sh and do whatever you want. inittab doesn't matter because /bin/sh is not known to read that file, and it doesn't ask for any password either. ;-)


