[Pkg-shadow-devel] Bug#443322: login: immediate 'Login incorrect' after unknown user name

ingo ingok at gmx.net
Thu Sep 20 15:29:00 UTC 2007


Package: login
Version: 1:4.0.18.1-11
Severity: normal

Hi,


when logging in with an unknown user name,
the login is immediately rejected with 'Login incorrect'.  

I suppose this is bad for security as it allows to
more easily guess valid user names.

IIRC, last time i consciously checked this (some time ago)
it was not possible to distinguish between
- username wrong 
- password wrong
- username and password wrong


Regards, ingo


Here a screen dump of a successful and a failed attempt:


        Ctrl-Alt-Delete for system halt

        Linux 2.6.22.5 (tty2)
        noo login: ingo
        Password:
        Last login: Thu Sep 20 17:13:11 CEST 2007 on tty2
        Linux noo 2.6.22.5 #3 Sun Aug 26 16:55:43 CEST 2007 i686

        The programs included with the Debian GNU/Linux system are free software;
        the exact distribution terms for each program are described in the
        individual files in /usr/share/doc/*/copyright.

        Debian GNU/Linux comes with ABSOLUTELY NO WARRANTY, to the extent
        permitted by applicable law.
        No mail.
        noo:~ % exit



        Ctrl-Alt-Delete for system halt

        Linux 2.6.22.5 (tty2)
        noo login: asdf

        Login incorrect
        noo login:




-- System Information:
Debian Release: lenny/sid
  APT prefers unstable
  APT policy: (500, 'unstable'), (1, 'experimental')
Architecture: i386 (i686)

Kernel: Linux 2.6.22.5
Locale: LANG=C, LC_CTYPE=C (charmap=ANSI_X3.4-1968)
Shell: /bin/sh linked to /bin/bash

Versions of packages login depends on:
ii  libc6                         2.6.1-5    GNU C Library: Shared libraries
ii  libpam-modules                0.99.7.1-4 Pluggable Authentication Modules f
ii  libpam-runtime                0.99.7.1-4 Runtime support for the PAM librar
ii  libpam0g                      0.99.7.1-4 Pluggable Authentication Modules l

login recommends no packages.

-- debconf-show failed





More information about the Pkg-shadow-devel mailing list