LinuxQuestions.org
Welcome to the most active Linux Forum on the web.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 08-23-2005, 08:12 AM   #1
patrick-slack
LQ Newbie
 
Registered: Aug 2005
Posts: 4

Rep: Reputation: 0
Root login suddenly dead


Hello,

I've been happily running Slack 10 on my laptop for about 9 months now, and beyond a few configuration hiccups I still havn't fixed, it's been working nicely as my day to day computer. I shutdown last night, and this morning I started up and logged in as my individual user, as always, without any problems.

Now, since I have returned from school, I have had to su and use the package 'switchto' to change from my school default settings to that of my home network. Problem is, it wouldn't accept my root password. Yes, I have ensured the password is actually being entered correctly.

After rebooting, and trying some different configurations, I still cannot login as root, or su, while my main user account works fine. From a prompt, it says "Login incorrect", and when trying to su from a console within X, "Authentication failure".

Any ideas why this may have changed all of a sudden, and what I can try to fix it? Searching hasn't turned up anything like my situation, and yes, I am very new at this.....thanks in advance!
 
Old 08-23-2005, 08:18 AM   #2
Rinish
Member
 
Registered: Apr 2005
Location: Bangalore
Distribution: Redhat, CentOS, AIX
Posts: 93

Rep: Reputation: 15
Try "login" command from single user mode. That will tell you what exactly your problem is!

Changing your password from single user mode is also a good idea :-)

/ Rinish (rinishriju)
 
Old 08-23-2005, 08:47 AM   #3
patrick-slack
LQ Newbie
 
Registered: Aug 2005
Posts: 4

Original Poster
Rep: Reputation: 0
Ok, so I passed the arguement "single" to my usual kernel config at boot with lilo, and after waiting a few minutes for my network connection attempts to timeout, it said switching to runlevel 1, which is single user mode.

Then, I am prompted as follows:

(none) login: root
Password:
login(pam_unix)[1593]: authentication failure; logname= uid=0 euid=0 tty=tty1 ruser=rhost= user=root
login[1593]: FAILED LOGIN 1 FROM FOR root, Authentication failure
Login incorrect


Hmmmmmmmm, what now?
 
Old 08-23-2005, 09:24 AM   #4
sundialsvcs
LQ Guru
 
Registered: Feb 2004
Location: SE Tennessee, USA
Distribution: Gentoo, LFS
Posts: 10,649
Blog Entries: 4

Rep: Reputation: 3934Reputation: 3934Reputation: 3934Reputation: 3934Reputation: 3934Reputation: 3934Reputation: 3934Reputation: 3934Reputation: 3934Reputation: 3934Reputation: 3934
Boot from a CD-ROM. Then start looking around.
 
Old 08-23-2005, 10:55 AM   #5
patrick-slack
LQ Newbie
 
Registered: Aug 2005
Posts: 4

Original Poster
Rep: Reputation: 0
I ended up booting off my cd and changing /etc/shadow to reset my root password (and having to learn some vi along the way ), so all is working for the moment.

but, the lingering question is still, why would the root password suddenly change like that? It was SOmething, as it had an encrypted form in the /etc/shadow, but it certainly wasn't anything of my setting. What exactly should I consider looking for?
 
Old 08-23-2005, 11:06 AM   #6
sundialsvcs
LQ Guru
 
Registered: Feb 2004
Location: SE Tennessee, USA
Distribution: Gentoo, LFS
Posts: 10,649
Blog Entries: 4

Rep: Reputation: 3934Reputation: 3934Reputation: 3934Reputation: 3934Reputation: 3934Reputation: 3934Reputation: 3934Reputation: 3934Reputation: 3934Reputation: 3934Reputation: 3934
Take the machine off the Internet, boot up in the CD-ROM and start checking for the rootkit.
 
Old 08-23-2005, 05:25 PM   #7
Tinkster
Moderator
 
Registered: Apr 2002
Location: earth
Distribution: slackware by choice, others too :} ... android.
Posts: 23,067
Blog Entries: 11

Rep: Reputation: 928Reputation: 928Reputation: 928Reputation: 928Reputation: 928Reputation: 928Reputation: 928Reputation: 928
Did you do any upgrades to your dropline installation
recently? I'm not saying that you haven't been rooted,
it's just that Slack normally doesn't use PAM at all ...


Cheers,
Tink
 
Old 08-24-2005, 08:52 AM   #8
zborgerd
Member
 
Registered: Mar 2004
Distribution: Slackware / Dropline GNOME
Posts: 378

Rep: Reputation: 30
Quote:
Originally posted by Tinkster
Did you do any upgrades to your dropline installation
recently? I'm not saying that you haven't been rooted,
it's just that Slack normally doesn't use PAM at all ...


Cheers,
Tink
Hmm. I'd be a bit concerned about this. Seeing as the standard user passwords work, it appears that PAM's authentication mechanisms are working properly. Seems more likely that someone has either taken over your machine or the password was changed/forgotten.

There wouldn't be any recent Dropline updates because we stopped building for Slackware 10.0 some time ago, but an update can certainly be forced. Have you been keeping up with the Slackware security updates?
 
Old 08-24-2005, 03:55 PM   #9
patrick-slack
LQ Newbie
 
Registered: Aug 2005
Posts: 4

Original Poster
Rep: Reputation: 0
Quote:
Originally posted by zborgerd

There wouldn't be any recent Dropline updates because we stopped building for Slackware 10.0 some time ago, but an update can certainly be forced. Have you been keeping up with the Slackware security updates?
I have not updated in a LONG while. This machine is mostly offline, so I havn't been very good about it. I've been going through things now with a rootkit detector, and havn't found anything so far, so I think I shall keep digging. Anything else worth checking for that anyone can think of off the top of their head? Very odd...
 
Old 08-25-2005, 07:03 AM   #10
zborgerd
Member
 
Registered: Mar 2004
Distribution: Slackware / Dropline GNOME
Posts: 378

Rep: Reputation: 30
Quote:
Originally posted by patrick-slack
I have not updated in a LONG while. This machine is mostly offline, so I havn't been very good about it. I've been going through things now with a rootkit detector, and havn't found anything so far, so I think I shall keep digging. Anything else worth checking for that anyone can think of off the top of their head? Very odd...
So you normally keep any services open to the outside? SSH? FTP? HTTP? Anything?
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Suddenly can't login fannymites Ubuntu 8 08-25-2005 07:12 PM
Dead mouse, suddenly hanasi SUSE / openSUSE 3 07-27-2005 08:29 PM
kybd input suddenly not working after login; OK if 'startx' from console OpenMacNews SUSE / openSUSE 7 02-10-2005 12:41 PM
X suddenly dead under Mdk10.0 RabidJackal Mandriva 7 04-25-2004 05:22 AM
cant login (keyboard dead) fwee Slackware 8 10-12-2003 11:40 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 01:51 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration