LinuxQuestions.org
Help answer threads with 0 replies.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Distributions > CentOS
User Name
Password
CentOS This forum is for the discussion of CentOS Linux. Note: This forum does not have any official participation.

Notices


Reply
  Search this Thread
Old 11-03-2021, 05:10 AM   #1
yyilmaz
LQ Newbie
 
Registered: Nov 2021
Posts: 2

Rep: Reputation: Disabled
Why is pam_faildelay.so not taking effect if user clicks cancel button?


Hi all, there is a problem to validate PAM faildelay rule on CentOS 7 Server with GUI installation. I have added one minute delay between failed login attempts. The first two lines in system-auth-ac and password-auth-ac files are as below:
Code:
auth        required      pam_env.so
auth        required      pam_faildelay.so delay=60000000
I have performed a test scenario as below:
- User enters wrong password
Now, signin button and password input field are inactive and login animation will be continuing during one minute ( I saw that login animation has ended after one minute if I have been waiting)
- User clicks the cancel button for example after ten seconds
Now, user selection screen is shown again (gnome login screen)
- User is selected again and enters wrong password

pam_faildelay.so is not taking effect if user clicks cancel button. What is the problem ? Are there any other pam files to edit in order to apply faildelay rule succesfully?

Thanks in advance

Last edited by yyilmaz; 11-03-2021 at 05:38 AM.
 
Old 11-18-2021, 03:41 PM   #2
rigor
Member
 
Registered: Sep 2003
Location: 19th moon ................. ................Planet Covid ................Another Galaxy;............. ................Not Yours
Posts: 705

Rep: Reputation: Disabled
If I understood correctly, what you described, it sounded to me as though you thought the faildelay should be activated when the User presses the Cancel button. Naturally I could be wrong, but my understanding is that "fail" is considered to be an incorrect password; that pressing the Cancel button is not classified as a "fail".
 
Old 11-19-2021, 12:52 AM   #3
yyilmaz
LQ Newbie
 
Registered: Nov 2021
Posts: 2

Original Poster
Rep: Reputation: Disabled
I have thought the same before I have decided to ask this question. pam_faildelay process should start as soon as wrong password is entered, shouldn't it ? If this attempt's owner is an attacker ? Can we say that attackers can enter wrong password then immediately can cancel how much they want?

For example, let's think that pam_faildelay time is set 60 seconds; attackers attempt to login, can understand the password is not correct because they are waiting unexpected time; then immediately can cancel. They can do this how much they want, can't ?

Thanks for your opinions.
 
Old 11-20-2021, 09:11 PM   #4
rigor
Member
 
Registered: Sep 2003
Location: 19th moon ................. ................Planet Covid ................Another Galaxy;............. ................Not Yours
Posts: 705

Rep: Reputation: Disabled
Quote:
Originally Posted by yyilmaz View Post
I have thought the same before I have decided to ask this question. pam_faildelay process should start as soon as wrong password is entered, shouldn't it ? If this attempt's owner is an attacker ? Can we say that attackers can enter wrong password then immediately can cancel how much they want?

For example, let's think that pam_faildelay time is set 60 seconds; attackers attempt to login, can understand the password is not correct because they are waiting unexpected time; then immediately can cancel. They can do this how much they want, can't ?

Thanks for your opinions.
Sorry, in your original post, I wasn't sure if you were saying that pam_faildelay wasn't working the way it was intended to work, or not as it should work. Sadly the two can be different. I was saying I thought the way it seems to be working, is the way that I thought it was intended to work. Naturally, as you described, as much as possible, there should be something which prevents someone from trying an endless number of incorrect passwords.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Synaptics TouchPad left mouse button clicks and scrolls at the same time Dark Riddle Linux - Laptop and Netbook 2 02-15-2012 04:08 AM
Mouse Middle Button Double Clicks SweetLou Linux - Hardware 3 12-12-2011 08:33 PM
Lack of Cancel Button When Editing Post blackhole54 LQ Suggestions & Feedback 2 09-10-2009 04:41 PM
Microsoft Optical Trackball 1.0 USB/PS2 Compatible not registering side button clicks phagocytosis Slackware 8 10-17-2008 05:23 PM
Glade GUI :: Cancel Button Code nomb Programming 1 03-15-2007 08:06 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Distributions > CentOS

All times are GMT -5. The time now is 01:48 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration