LinuxQuestions.org
Visit Jeremy's Blog.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 05-10-2004, 02:37 PM   #1
hus
Member
 
Registered: Dec 2003
Location: Bangkok- Thailand
Distribution: Mandriva 10.0,Fedora Core 4
Posts: 79

Rep: Reputation: 15
Shadow file is important?


I think it's not nescesary if your passwd file is set permission
to not readable and writeable.
 
Old 05-10-2004, 03:04 PM   #2
jpbarto
Senior Member
 
Registered: Mar 2003
Location: Pittsburgh, PA
Distribution: Gentoo / NetBSD
Posts: 1,251

Rep: Reputation: 45
If your password file is not readable by anyone then how will you log in?
 
Old 05-10-2004, 04:00 PM   #3
iainr
Member
 
Registered: Nov 2002
Location: England
Distribution: Ubuntu 9.04
Posts: 631

Rep: Reputation: 30
Not to mention how will your shell know which username maps onto which UID, or any of the other information held in the passwd file.
 
Old 05-12-2004, 09:44 AM   #4
hus
Member
 
Registered: Dec 2003
Location: Bangkok- Thailand
Distribution: Mandriva 10.0,Fedora Core 4
Posts: 79

Original Poster
Rep: Reputation: 15
jpbarto I can login ,


localhostlogin: hus
password:
Last login :Tue May 11 20:20:02 on tty1
id:cannot find name for user ID 500
id:cannot find name for group ID 500
id:cannot find name for user ID 500

[I have no name!@localhost]$
[I have no name!@localhost]$ who am i
hus tty1 may 11 20:23
[I have no name!@localhost]$less /etc/passwd
/etc/passwd: Permission denied

and I can do anythings like hus

PS: passwd&group file is not readable for all
 
Old 05-13-2004, 09:46 AM   #5
jpbarto
Senior Member
 
Registered: Mar 2003
Location: Pittsburgh, PA
Distribution: Gentoo / NetBSD
Posts: 1,251

Rep: Reputation: 45
Perhaps I don't know enough about the login process, however, the login (getty?) is probably using your shadow file to verify the login and giving you a bash. However if you were to eliminate the shadow file as the subject of this thread would imply, and store the passwords in the /etc/passwd which is not readable by anyone then you would not be able to login.

But then I've never tested this, it just seems to me to be what would happen. Feel free to give it a shot, just be sure to have a boot disk laying around somewhere in case I'm right.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
/etc/shadow file missing Computergirl24 Linux - Software 3 08-28-2008 06:28 AM
shadow file os2 Linux - Security 3 10-18-2005 03:20 PM
CHPASSWD Help! Shadow File! clintonm9 Linux - Software 3 04-17-2004 09:15 AM
shadow file stevee Linux - Security 1 10-07-2003 10:11 AM
shadow file? tjm Linux - Security 4 09-15-2003 04:23 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 10:45 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration