LinuxQuestions.org
Welcome to the most active Linux Forum on the web.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Other *NIX Forums > Solaris / OpenSolaris
User Name
Password
Solaris / OpenSolaris This forum is for the discussion of Solaris, OpenSolaris, OpenIndiana, and illumos.
General Sun, SunOS and Sparc related questions also go here. Any Solaris fork or distribution is welcome.

Notices


Reply
  Search this Thread
Old 07-31-2003, 11:28 AM   #1
hopbalt
Member
 
Registered: Jul 2003
Posts: 39

Rep: Reputation: 15
Solaris 5.1 security issues


I am a novice user so keep that in mind

We have a Sun Solaris 5.1 machine in which both the CD and the root password have been lost.

While browsing around on the machine, I ran across a file called sulogin which lets you enter into maintenance mode. Since I dont know what the superuser or root password is, I figured that I wouldnt be able to use it.

However, I was shocked and delighted when it actually worked. It gives the following message:

"Warning: root password not set, entering maintenance mode"

My excitement soon abated when I realized that I still didnt have root powers. It wont let me use chmod, it wont let me edit some files with vi. I thought maintenance mode would give me some of the same powers as root or superuser, but apparently not. It wont let me do any of the stuff that i need it to.

I am using telnet to connect to this machine. When I tried to login as root with no password, it just closes automatically. It doesnt even say that password is not correct, its as if the machine is refusing to let anyone log in as root even if the password is right.

Are you not allowed to login as root remotely, or is the sulogin program lying to me when it says the root password has not been set?
 
Old 07-31-2003, 05:23 PM   #2
fishsponge
Member
 
Registered: Apr 2003
Location: Cambridge, UK
Distribution: Debian/Solaris
Posts: 147

Rep: Reputation: 15
it sounds to me like the root password isn't set... lol, have you actually tried logging in as a standard user, and typing:
Code:
su - root
you cannot telnet into machines as root straight away - this is a security feature. you need a user account with permissions to run the "su" command to switch user to become root. tried that yet?
 
Old 08-01-2003, 06:52 AM   #3
hopbalt
Member
 
Registered: Jul 2003
Posts: 39

Original Poster
Rep: Reputation: 15
Quote:
Originally posted by fishsponge
it sounds to me like the root password isn't set... lol, have you actually tried logging in as a standard user, and typing:
Code:
su - root
you cannot telnet into machines as root straight away - this is a security feature. you need a user account with permissions to run the "su" command to switch user to become root. tried that yet?
Well I tried su - root from telnet, and then it asked for a password. I just pressed enter and it said "incorrect login"

I then went to the machine console and tried to login as root, just pressing enter when it asked for password. No luck, I get the "incorrect login" message.

Thats what I dont understand about this. The sulogin program is saying the root password is blank, yet when I try to log in as root, even from the machine console itself, it says login incorrect.

Sulogin must be a corrupted program or something
 
Old 08-01-2003, 07:47 AM   #4
stickman
Senior Member
 
Registered: Sep 2002
Location: Nashville, TN
Posts: 1,552

Rep: Reputation: 53
Re: Solaris 5.1 security issues

Quote:
Originally posted by hopbalt
Are you not allowed to login as root remotely, or is the sulogin program lying to me when it says the root password has not been set?
Whether or not you can login as root remotely depends on how the system is configured.

sulogin is launched when the system is coming up and there is something wrong with the system. That's the program that gives you the choice of CTRL-D to continue or entering root's password to fix the problem. It is invoked by init and not meant to be run by a user. It did not put you in maintenance mode when you invoked it as a user.

On a Solaris system, there is one simple test for determining whether or not the root password is blank. If you try to login at the console, the system will not prompt for a password. Since your systems prompts for a password, it is set.
 
Old 08-01-2003, 11:26 AM   #5
hopbalt
Member
 
Registered: Jul 2003
Posts: 39

Original Poster
Rep: Reputation: 15
What if I physically remove the hard drive and put it on another machine?

Do you HAVE to be root on the new machine to mount a new hard drive or can you do it as any user?
 
Old 08-01-2003, 12:14 PM   #6
stickman
Senior Member
 
Registered: Sep 2002
Location: Nashville, TN
Posts: 1,552

Rep: Reputation: 53
You will need root privelages to build the device files for the drive on the new machine if they do not exist. You wall also need root to mount the file systems.
 
Old 08-04-2003, 05:31 AM   #7
fishsponge
Member
 
Registered: Apr 2003
Location: Cambridge, UK
Distribution: Debian/Solaris
Posts: 147

Rep: Reputation: 15
Quote:
Originally posted by hopbalt
The sulogin program is saying the root password is blank, yet when I try to log in as root, even from the machine console itself, it says login incorrect.
are you sure that the 'sulogin' program isn't saying that the password you entered is blank? if you enter no password, then the password entered would be blank, right?

i could be going off on a tangent here... lol
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
porting issues from solaris to linux vinod_indus Programming 2 09-12-2005 11:05 AM
Jumpstart issues with solaris 10 genlee Solaris / OpenSolaris 0 04-05-2005 11:05 AM
Solaris 10 x86 CIS security scan ghouliajoolia Solaris / OpenSolaris 5 02-11-2005 10:02 AM
NFS issues between ES 3.0 and Solaris 8 EdR Linux - Newbie 2 11-10-2004 01:38 PM
Solaris 9 web browser issues. PF_The_Wall Solaris / OpenSolaris 3 09-24-2004 12:01 AM

LinuxQuestions.org > Forums > Other *NIX Forums > Solaris / OpenSolaris

All times are GMT -5. The time now is 06:04 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration