Re: (Free 7.2) "su -l" didnt prompt password.Is it possbile?

看板FB_security作者時間13年前 (2012/06/19 02:01), 編輯推噓0(000)
留言0則, 0人參與, 最新討論串6/6 (看更多)
18.06.2012 18:32, Chris Rees ???????: > > > On Jun 18, 2012 2:34 PM, "Budnev Vladimir" <vladimir.budnev@gmail.com > <mailto:vladimir.budnev@gmail.com>> wrote: > > > > Hello everyone. > > We'v noticed some strange situation. After reboot and login, system > didn't ask for password while switchig with su -l. > > > > In details, there was root login from terminal and one from ssh. > > Terminal login was directly as root(via ip-console), and ssh was as > user, then attemped switch to root with su -l, and there were NO > password request,no prompt at all. At the same time login from > terminal accepted root password, first I thought that means password > wasn't empty, but system even with empty password should print > "Password:"..and that time it was nothing absolultey. > > Empty password behaviour is for no prompt, so what you are seeing is > normal, and means that you did indeed have a empty password. > Interesintg could it be that master.passwd file corrupted (after power shutdown) and fsck corrected in background.. which resulted in such behaviour. The strange thing with possibly empty password is that login from ip-console accepted correct password. So dont sure about empty...It seems like su was accepting any password at that time. > > Check your logs very carefully over the past few weeks to make sure no > one has broken in. > Yeah, seems we are forced to mount disks to another system and check for changes in critical system tools. Argh....and then anyway redeploy system. > > Chris > _______________________________________________ freebsd-security@freebsd.org mailing list http://lists.freebsd.org/mailman/listinfo/freebsd-security To unsubscribe, send any mail to "freebsd-security-unsubscribe@freebsd.org"
文章代碼(AID): #1FtspVxD (FB_security)
討論串 (同標題文章)
文章代碼(AID): #1FtspVxD (FB_security)