LinuxQuestions.org
Welcome to the most active Linux Forum on the web.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 12-06-2011, 05:38 AM   #1
hydraMax
Member
 
Registered: Jul 2010
Location: Skynet
Distribution: Debian + Emacs
Posts: 467
Blog Entries: 60

Rep: Reputation: 51
pam-mysql: password in world readable file?


I'm not yet a PAM guru (more like a wannabe n00b) but was looking into using pam-mysql in one situation. But something doesn't quite make sense to me: if I use pam-mysql in a PAM config file, then I must include the username and password for the authentication database in the module arguments, correct? But all these PAM files are world-readable, yes? Isn't this an insecure arrangement?
 
Old 12-07-2011, 04:48 PM   #2
acid_kewpie
Moderator
 
Registered: Jun 2001
Location: UK
Distribution: Gentoo, RHEL, Fedora, Centos
Posts: 43,417

Rep: Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985
see the "crypt" option. http://pam-mysql.sourceforge.net/Doc...age-readme.php

Nope scratch that, that's the user password still... I really can't find anything about this. I guess you just need to craft a user with the exactly right privileges very carefully. Even saying that though, the module expects to be able to write data... From where I'm sitting, I'd say your concerns are totally justified.

Last edited by acid_kewpie; 12-07-2011 at 04:51 PM.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Use PAM for MySQL auth? (I.e., password-less MySQL access?) hydraMax Linux - Security 4 04-05-2011 09:26 PM
Why do I have to make these files world readable? Red Squirrel Linux - Software 1 03-18-2011 06:18 AM
World Readable Home Directories carlosinfl Debian 7 06-24-2008 05:48 AM
Is ".gz" archive file considered "World-Readable"? NightSky Linux - Newbie 4 12-06-2007 05:21 PM
Sensitive MySQL info in readable PHP file dubya Programming 7 03-13-2006 03:31 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 12:17 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration