LinuxQuestions.org
Latest LQ Deal: Latest LQ Deals
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 04-13-2016, 06:22 PM   #1
gglq000
Member
 
Registered: Mar 2012
Posts: 65

Rep: Reputation: Disabled
need to find out by sniffing the value of password being sent over terminal


i have a dilemma. I have live rhel system running which I can login through after enabling serial console redirection.
basically root + password.

however i am automating the login process using pythin pexpect interactive module which can emulate the login process. it essentially works except the login is always denied. I double checked everything in the code and can find any fault, it always sends the username when prompted and sends correct password when prompted.

that means i need to do some debugging. is there any way i can sniff the value of password being received from the linux side? as always the login is over the ssh protocol?

as i said the serial console redirection is done through ssh connection that redirects the whole display terminal not just linux and the automation module uses this out-of-band terminal to interact with the linux.

so I can not use this terminal to do debugging. if i manage to login through host os IP and do some sniffing, what options available? Thanks.,
 
Old 04-14-2016, 01:32 AM   #2
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
Creds sniffing is frowned upon (for good reason) and a questionable tactic if you have not exhausted your other options. On top of that root logins are (rightfully so) subject to restrictions and its not clear from your case (not having seen you check system configs, securetty, PAM, system logs etc, etc) if that's what's blocking what you try to do. I strongly suggest you first test your process with an unprivileged user account to be able to validate the login process, run your code in debug mode and post code snippets / output to support your case.
 
Old 04-14-2016, 03:17 AM   #3
zhjim
Senior Member
 
Registered: Oct 2004
Distribution: Debian Squeeze x86_64
Posts: 1,748
Blog Entries: 11

Rep: Reputation: 233Reputation: 233Reputation: 233
Going SSH why not use key login instead of password?
 
Old 04-14-2016, 04:01 AM   #4
gglq000
Member
 
Registered: Mar 2012
Posts: 65

Original Poster
Rep: Reputation: Disabled
i figured out thanks.
i was sending password and ENTER char in a separate line. That obviously introduced some char in between. I had to send password+enter char in one line.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
terminal password redxpoppy Linux - Newbie 5 08-16-2015 05:56 AM
Terminal requiring a password maddtessmath Linux - Newbie 2 11-12-2014 05:34 PM
[SOLVED] Gnome terminal 2.1.0, centos 5 - how to 'find' text listed on terminal screen linuxquestions_forum_use Linux - Newbie 2 12-21-2010 08:35 PM
Password Recovery in Edubuntu 7.04 - In Terminal, Root Login : su , password : ????? farhannaeem13 Linux - Security 3 11-30-2007 09:59 AM
Sniffing password?!?! nostromo Linux - Wireless Networking 11 01-18-2005 03:57 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 05:51 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration