home *** CD-ROM | disk | FTP | other *** search
- Path: sparky!uunet!usc!cs.utexas.edu!chinacat!rpp386!jfh
- From: jfh@rpp386.lonestar.org (John F. Haugh II)
- Newsgroups: comp.security.misc
- Subject: Re: GNU su doesn't restrict root access? Why?
- Message-ID: <21839@rpp386.lonestar.org>
- Date: 7 Nov 92 15:37:30 GMT
- References: <21805@rpp386.lonestar.org> <720912396snx@nemesys.demon.co.uk>
- Reply-To: jfh@rpp386.cactus.org (John F. Haugh II)
- Organization: Los Tejanos SCUBA Club and Beer Joint, Austin, Tejas
- Lines: 28
-
- In article <720912396snx@nemesys.demon.co.uk> gvm@nemesys.demon.co.uk (Granville Moore) writes:
- >I'm not sure what you mean by a non-distributed system, here. Assuming
- >you mean "distributed", then if it uses NIS, or similar, then only
- >the encrypted passwords are copied to the other systems, so each one
- >will have exactly the same salt as it had before, and there is no
- >change in vulnerabilty (from this point of view, anyway). If the
- >systems don't use NIS, then the password lists are independent, and
- >your cracker has a list of 20 to work with, rather than 10. He/she
- >therefore naturally has a better chance of getting 2 salts which
- >coincide. It still doesn't help a lot, though - about a 1 in 20
- >chance of getting 2 the same, and 18 different. The chances of 3
- >the same will be about 1 in 4000ish.
-
- By "non-distributed" I mean schemes by which the password file isn't
- shared by all systems through a central "distributed" database. This
- could be Andrew or NIS or ... Each /etc/passwd is maintained on its
- own. Updating your password means going to <N> different machines
- and saying "passwd".
-
- In this situation if you have 2 machines with 10 users all sharing
- root but with different account names, yes, the odds are not much
- better. But make that 10 or 20 machines and suddenly the odds get
- to swing in favor of the cracker. With 20 machines and only 1 user,
- it doesn't matter - even if two of them have the same salt, you still
- have to find out which SINGLE password it is.
- --
- John F. Haugh II [ TSAKC ] !'s: ...!cs.utexas.edu!rpp386!jfh
- Ma Bell: (512) 251-2151 [ DoF #17 ] @'s: jfh@rpp386.cactus.org
-