home *** CD-ROM | disk | FTP | other *** search
- Path: sparky!uunet!cis.ohio-state.edu!ucbvax!agate!linus!aquila.sni-usa.com!news.sni.de!offbeat!mboen
- From: mboening.pad@sni.de (Martin Boening)
- Newsgroups: alt.security
- Subject: Re: passwd security check
- Message-ID: <mboen.712487508@offbeat>
- Date: 30 Jul 92 09:11:48 GMT
- References: <1992Jul22.190827.30077@iitmax.iit.edu> <Brt2n3.GE9@solbourne.com> <14kib3INN18l@moe.ksu.ksu.edu> <Brt8GH.Guz@solbourne.com>
- Sender: news@nixpbe.sni.de
- Organization: Siemens Nixdorf Info.Sys. AG, Paderborn, Germany
- Lines: 34
-
- In <Brt8GH.Guz@solbourne.com> imp@solbourne.com (Warner Losh) writes:
-
- [ stuff deleted ]
-
- >same person, then I might agree with you. However, it is quite
- >possible that two people indepently chose batman! (or r0bin!) as their
- >password after seeing the same movie. I'm still not convinced that
- >this is a real hole....
-
- Even if two people choose the same password, the chances are small that
- both will have the same encrypted password in their passwd file. This is
- because each encrypted password consists of 2 letters salt and the rest
- is the real encryption for the password entered. The salt is calculated
- in abstruse ways from process ids of passwd processes, times, and I know
- not what random factors. It will be different for most invocations of
- passwd, therefore the encrypted version of the password will be
- different.
-
- Conclusion: if you do find the same encrypted version of a password for
- two or more entries in a /etc/passwd file, chances are that the password
- was copied in from the first to the second entry. This can happen when a
- lazy sys admin simply copies one user entry to another and then changes
- the fields that need changing.
-
- It should never occur if new accounts are generated using some sysadmsh
- like interface.
-
- So long,
- Martin
- --
- Email: in the USA -> mboening.pad@sni-usa.com
- outside USA -> mboening.pad@sni.de
- Paper Mail: Martin Boening, Siemens Nixdorf Informationssys. AG, SNI STO SI 325,
- Pontanusstr. 55, 4790 Paderborn, W.-Germany (Phone: +49 5251 835641)
-