LinuxQuestions.org
Welcome to the most active Linux Forum on the web.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - General
User Name
Password
Linux - General This Linux forum is for general Linux questions and discussion.
If it is Linux Related and doesn't seem to fit in any other forum then this is the place.

Notices


Reply
  Search this Thread
Old 06-09-2003, 10:45 PM   #1
Halz
LQ Newbie
 
Registered: Oct 2001
Posts: 23

Rep: Reputation: 15
Strange password handling..


I just changed the password for root with 'passwd' to, for example, from 'qwerty' to 'qwertyasdf'; I basically just added more characters to the end of the current password.

The next time I logged into root, I mistakenly typed in the old password (qwerty).. however.. it was accepted, and I was able to log in.. so I logged out, and then tried to login again with the 'qwertyasdf' password, and it also accepted it.

So, I tried to log in again as root but this time with the password as 'qwertyasdfkjnqweoin' (etc, just garbage after the 'password') and it let me in.. so then I tried to find what the shortest password I could enter was, and it turned out to be 'qwert'.. basically, it was the old password I had been using for a very long time, minus the last character.

I then changed the root password to something that did not use the previous password; '1234567', and it, expectedly, denied the previous 'qwerty' password, and also denied '1234567kjsdkfbdfgb' (and some garbage after the password). Just as I would expect.

With another account on the machine that was using the same 'qwerty' password, its the same case.. I can type in *whatever* after the 'real' password.. and changing it with anything that includes the original password has no effect.

I've also tried to delete the password, with 'passwd -d', and change it to no avail.

I then also changed the password to '1q2w3e4r5t6y7u8i9o0p', tried to log in, and it allowed anything beyond '1q2w3e4r'...
 
Old 06-10-2003, 04:08 AM   #2
jdc2048
Member
 
Registered: Jul 2002
Distribution: Redhat, Gentoo, Solaris, HP-UX, etc...
Posts: 391

Rep: Reputation: 30
If you are logging into this machine via a text login, then I believe you are seeing the 8-character limit that is imposed on passwords. You can type in anything you want after the first 8 characters of your password and it will accept it. I find this a good way to vent some steam from time to time... you know ... like 'passwordihatemyboss' or 'passwordheissuchanidiot'. Have fun with it!
 
Old 06-10-2003, 06:11 AM   #3
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
If you're using shadowed passwords, passwd should accept over 8 chars. Grep your /etc/pam.d/{passwd,login} for "shadow" to find out.
 
Old 06-10-2003, 06:08 PM   #4
Halz
LQ Newbie
 
Registered: Oct 2001
Posts: 23

Original Poster
Rep: Reputation: 15
Ah, thanks.. not being shadowed was it
 
Old 06-10-2003, 06:36 PM   #5
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
Can you tell me which distribution+release this is that doesn't use shadow passwds by default, btw? Would be good to know.
 
Old 06-19-2003, 02:17 PM   #6
Halz
LQ Newbie
 
Registered: Oct 2001
Posts: 23

Original Poster
Rep: Reputation: 15
This is on a Mandrake 8.1 system. When installing, theres an option that asks how the security should be setup and I think anything less than the 'paranoid' setting doesn't enable shadow passwords.
Sorry about the late reply..
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
VERY strange C# event handling problem, please read. jwn7 Programming 2 10-20-2005 10:28 AM
strange MYSQL password Encrypted max_tcs Linux - Software 2 03-30-2005 03:45 AM
strange MYSQL password Encrypted max_tcs Linux - Newbie 2 03-28-2005 04:39 PM
Strange root password problem harken Linux - Security 3 02-17-2005 01:12 PM
strange, strange alsa problem: sound is grainy/pixellated? fenderman11111 Linux - Software 1 11-01-2004 05:16 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - General

All times are GMT -5. The time now is 12:27 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration