LinuxQuestions.org
Share your knowledge at the LQ Wiki.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 01-16-2014, 08:26 AM   #1
tomatopancake
LQ Newbie
 
Registered: Jul 2012
Posts: 2

Rep: Reputation: Disabled
winbind bug allowing login without password


I have a Centos 5.3 server being used for subversion. It is bound to an Active Directory using winbind (samba-winbind 3).

There is sometimes a lag when logging in via ssh before the password prompt is shown. Two days ago while waiting to be asked for the root password I hit ctrl+c, the lag continued for another couple seconds, then I was given the root prompt -- I did not enter a password though it still echoed the "root@hosts's password:" line.

I thought I was mistaken and tried to do it again, but the lag only happens when it's been a while since the last login.

Yesterday I tried again and the exact same thing happened.

I am going to try it again today to see if it is happening as I believe it is. My question is what logs or configuration settings I should look at to see what is going on. /var/log/secure showed nothing unusual from the occurrence yesterday; it said the root password was accepted.

I did a couple searches and found no bugs similar to this.

Any input is appreciated.
 
Old 01-18-2014, 02:56 AM   #2
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
Quote:
Originally Posted by tomatopancake View Post
Any input is appreciated.
Well in that case...


Quote:
Originally Posted by tomatopancake View Post
I have a Centos 5.3 server
Then you're 7 updates behind (CentOS has been at 5.10 for some time now). Not good!


Quote:
Originally Posted by tomatopancake View Post
(..) while waiting to be asked for the root password
If you're logging in locally that's fine. Remember root should not log in over any networks: use an unprivileged account and then elevate privileges the usual way.


Quote:
Originally Posted by tomatopancake View Post
I am going to try it again today to see if it is happening as I believe it is.
Why make the effort if you didn't reconfigure things first?


Quote:
Originally Posted by tomatopancake View Post
My question is what logs or configuration settings I should look at to see what is going on.
CentOS being related to RHEL that would mean your PAM stacks in /etc/pam.d/, the changes you made to make winbind work and especially the effect of having any "auth sufficient" lines.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Winbind password problem resmania Linux - Server 1 08-19-2008 03:33 AM
Locking out a user when password expires, but allowing them to change their password kaplan71 Linux - Security 5 06-27-2008 07:12 PM
After changing Windows AD password Samba\Winbind still uses old password Criller Linux - Security 2 02-28-2008 04:14 AM
Allowing certain IPs to login SAMBA without password Panagiotis_IOA Linux - Networking 0 06-07-2006 06:40 PM
Checking a password with PAM/Winbind? quill18 Programming 1 05-25-2005 03:12 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 08:11 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration