Linode Forum
Linode Community Forums
 FAQFAQ    SearchSearch    MembersMembers      Register Register 
 LoginLogin [ Anonymous ] 
Post new topic  Reply to topic
Author Message
PostPosted: Thu Sep 18, 2008 12:37 pm 
Offline
Senior Newbie

Joined: Fri Sep 14, 2007 1:40 pm
Posts: 17
Hi,

Since I'm very concerned with security and Lish allows password authentication I decided to get an extra-strong password.

Accordingly to Web Linode Manager: "Passwords must be alphanumeric and/or punctuation, 6-16 characters in length." So I chose a password with 12 characters, pretty random.

The problem is, whenever I login to Lish, it grants me access after the first 8 characters!! :roll:

Example:

I set my password to: lInOdE-lIsh-007

Then if I enter: lInOdE-l

I'm already in!

Please, try for yourself. Well, this is not *very* serious, but a stronger password, with the 16 characters advertised would be away better.


Top
   
 Post subject: 1234567890
PostPosted: Thu Sep 18, 2008 12:58 pm 
Offline
Linode Staff
User avatar

Joined: Tue Apr 15, 2003 6:24 pm
Posts: 3090
Website: http://www.linode.com/
Location: Galloway, NJ
The bug looks to be in chpasswd(8), which is an easily scriptable password changer. It looks to be using an older encryption algorithm that only cares about the first 8 characters.

We'll get this fixed ASAP.

-Chris


Top
   
 Post subject: Why not PKs?
PostPosted: Thu Sep 18, 2008 1:00 pm 
Offline
Senior Newbie

Joined: Fri Dec 07, 2007 11:04 am
Posts: 15
ICQ: 194918
WLM: hotgazpacho@hotmail.com
Yahoo Messenger: hotgazpacho
AOL: SailorWill
Location: Tampa, FL
If you're that concerned with security, why aren't you using you SSH Public Key to log in to LISH?

Good catch, though.


Top
   
 Post subject:
PostPosted: Thu Sep 18, 2008 1:23 pm 
Offline
Senior Newbie

Joined: Fri Sep 14, 2007 1:40 pm
Posts: 17
Thank you, caker.

hotgazpacho, the problem is, what's the point in having a extra-secure lock in a door for which you have the key, when your house has simple glass windows (and you live on the ground floor)?

I might use a SSH Public Key, but since it's impossible to disable password logins, it doesn't enforce security. :)

Well, I have direct SSH login enabled to my machine and there I'm using SSH Keys with Passphrase, since I disabled password login.


Top
   
 Post subject:
PostPosted: Thu Sep 18, 2008 2:35 pm 
Offline
Linode Staff
User avatar

Joined: Tue Apr 15, 2003 6:24 pm
Posts: 3090
Website: http://www.linode.com/
Location: Galloway, NJ
OK, it's now fixed (on subsequent password reset).

Thanks for letting us know about this.

-Chris


Top
   
 Post subject:
PostPosted: Fri Sep 19, 2008 12:22 am 
Offline
Junior Member

Joined: Sat Jan 05, 2008 2:40 am
Posts: 43
Is it true that until an account password is reset, all users will still be hit by this?

If so, should there perhaps be an advisory on the blog?


Top
   
Display posts from previous:  Sort by  
Post new topic  Reply to topic


Who is online

Users browsing this forum: No registered users and 6 guests


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum

Search for:
Jump to:  
RSS

Powered by phpBB® Forum Software © phpBB Group