Results 1 to 6 of 6

Thread: login with wrong password

  1. #1
    Join Date
    Jun 2007
    Beans
    25

    login with wrong password

    I've just noticed that my Ubuntu file server let me login with the wrong password

    My password is 9 characters long but if i miss of the last letter (ie only enter the first 8 ) it still logs me in.

    Any idea's why?

  2. #2
    Join Date
    Nov 2006
    Location
    40.31996,-80.607213
    Beans
    Hidden!
    Distro
    Ubuntu

    Re: login with wrong password

    That doesn't make sense.
    "Security lies within the user of who runs the system. Think smart, live safe." - Dr Small
    Linux User #441960 | Wiki: DrSmall

  3. #3
    Join Date
    Nov 2007
    Location
    London, England
    Beans
    5,484
    Distro
    Xubuntu 14.04 Trusty Tahr

    Re: login with wrong password

    What protocol are you using to log in with?
    VNC only checks the first 8 characters.

  4. #4
    Join Date
    Jun 2007
    Beans
    25

    Re: login with wrong password

    I mainly use SSH and webmin for remote admin of the machine which both allow me to login without the last character. It also does this when I connect to my e-mails (using Dovecot IMAP) but samba will only accept the full password!!

  5. #5
    Join Date
    Dec 2006
    Location
    Chicago
    Beans
    3,839

    Re: login with wrong password

    Sounds like your /etc/shadow file has DES hashes. Hardy seems to use MD5 hashes by default. What is the output of
    Code:
    sudo getent shadow chrisdeeley|cut -d : -f 2|cut -c 1,2,3
    If it doesn't start with a "$", that is a DES hash, and only the first 8 characters of your password are used. What version of ubuntu are you running. What version were your running when you set that password? Try resetting it.
    Code:
    sudo passwd chrisdeeley
    Also, check this file
    Code:
    grep MD5_CRYPT_ENAB /etc/login.defs
    Last edited by cdenley; June 4th, 2008 at 10:25 PM.

  6. #6
    Join Date
    Jun 2007
    Beans
    25

    Re: login with wrong password

    I was and still am running 7.10 gutsy. I just reset the password and now everything's back to normal. I don't understand why though because another user that I set up at the same time also has a long password yet when i tested it, I could only log in with the full password.

    Everything appears to be back to normal. I'll try it again in the morning and see what happens.

    Thanks for your help

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •