LinuxQuestions.org
Review your favorite Linux distribution.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 03-12-2006, 10:32 AM   #1
furfurdemon666
Member
 
Registered: Mar 2004
Posts: 171

Rep: Reputation: 30
Exclamation Admin Password readable by all users on Ubuntu Breezy?


Would you want your Admin password in plain text on your hard drive readable by any user?

If you're using Ubuntu Breezy, this post on the Ubuntu Forums may be of interest.

In short, a user posted about the admin username/password being readable by any user in plain text in the file:

/var/log/installer/cdebconf/questions.dat

Check your own system and see for yourself.

Edit: See also: "Bug #34606 in Ubuntu: "Administrator root password readable in cleartext on Breezy"

Comments?

Last edited by furfurdemon666; 03-12-2006 at 11:06 AM.
 
Old 03-12-2006, 10:43 AM   #2
uselpa
Senior Member
 
Registered: Oct 2004
Location: Luxemburg
Distribution: Slackware, OS X
Posts: 1,507

Rep: Reputation: 47
Same on Kubuntu. And file is world-readable.
Well done...
 
Old 03-12-2006, 11:56 AM   #3
Hangdog42
LQ Veteran
 
Registered: Feb 2003
Location: Maryland
Distribution: Slackware
Posts: 7,803
Blog Entries: 1

Rep: Reputation: 422Reputation: 422Reputation: 422Reputation: 422Reputation: 422
Hmm. It isn't quite as straightforward as that. I support a couple of Ubuntu boxes for friends (both Breezy Badger) and while the admin username is in that file, the passwords definitely are not. Both are pretty stock installs of Ubuntu with very little customization. There has got to be a bit more to this story.
 
Old 03-12-2006, 01:26 PM   #4
furfurdemon666
Member
 
Registered: Mar 2004
Posts: 171

Original Poster
Rep: Reputation: 30
Quote:
Originally Posted by Hangdog42
Hmm. It isn't quite as straightforward as that
Actually, for many people, it is. In fact, this bug has been confirmed and is listed as critical:

https://launchpad.net/distros/ubuntu/+bug/34606

Last edited by furfurdemon666; 03-12-2006 at 01:27 PM.
 
Old 03-13-2006, 09:06 AM   #5
scuzzman
Senior Member
 
Registered: May 2004
Location: Hilliard, Ohio, USA
Distribution: Slackware, Kubuntu
Posts: 1,851

Rep: Reputation: 47
This bug has been fixed. This post on the Ubuntu forum indicates that it was a problem in the install process that has not only been fixed in the upcoming Dapper Drake release, but there is a patch already available. To update yourself, simply install the latest version of passwd (passwd-4.0.3-37ubuntu8).
 
Old 03-13-2006, 05:35 PM   #6
Capt_Caveman
Senior Member
 
Registered: Mar 2003
Distribution: Fedora
Posts: 3,658

Rep: Reputation: 69
WARN: Ubuntu Admin Password Leak

A potentially critical vulnerability has been identified in Ubuntu 5.10 (Breezy Badger). The Ubuntu installer stores in plaintext the username and password of the first user created during installation in a world-readable file. As this user is granted full sudo rights by default, the account has administrative privileges. It has also been reported that the actual root password will appear if the installation was performed in 'expert mode'. Some uncertainty regarding the significance of this bug has led some vulnerability reports to classify it as minor, however it does appear to allow compromise of an administrative account by a local user.

http://secunia.com/advisories/19200/
http://www.securityfocus.com/brief/161
http://www.ubuntu.com/usn/usn-262-1
http://www.ubuntuforums.org/showthread.php?t=143334

Last edited by Capt_Caveman; 03-13-2006 at 05:36 PM.
 
Old 03-13-2006, 05:45 PM   #7
Capt_Caveman
Senior Member
 
Registered: Mar 2003
Distribution: Fedora
Posts: 3,658

Rep: Reputation: 69
Thanks for reporting this. Merging this thread with the stickied post.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
admin password amcarthur *BSD 10 06-20-2005 08:26 PM
admin. password mark1346 Linux - Software 2 08-05-2003 05:24 PM
How to retrieve Admin password? gogo Linux - General 9 03-27-2003 02:53 PM
Recovering Lost Admin. Password Mr Neroazzurri Linux - Security 4 03-14-2003 05:26 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 09:58 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration