Re: master.passwd -- securing

From: Rhys John (elite_bizkit_at_hotmail.com)
Date: 12/18/03

  • Next message: Hanspeter Roth: "Re: identity using send-pr with dynamic address"
    To: freebsd-questions@freebsd.org
    Date: Thu, 18 Dec 2003 11:44:14 +0000
    
    

    Both accounts are now active but i would like to remove the encrypted
    password from master.passwd and replace it with a *. Is this possible with
    "vipw"?

    Thanks for your reply hugle

    >From: hugle <hugle@vkt.lt>
    >Reply-To: hugle <hugle@vkt.lt>
    >To: freebsd-questions@freebsd.org
    >Subject: Re: master.passwd -- securing
    >Date: Thu, 18 Dec 2003 03:39:18 -0800
    >
    >RJ> Ive been playing with "vipw" trying to change passwords into "*" for a
    >RJ> slightly higher level of security but ran into some very big problems.
    >From
    >RJ> reading through the FreeBSD handbook it seemed all i had to do was
    >replace
    >RJ> the encrypted password with *, which is what i did. I thought it seemed
    >a
    >RJ> bit odd but continued anyway. Foolishly (although i was quite tired) i
    >did
    >RJ> this to both my user account and root. So they both had * as their
    >password
    >RJ> and looked the same as every other entry in the file. I saved it and
    >"vipw"
    >RJ> updated the database so i thought all was well and logged off to
    >check...
    >RJ> big mistake! The net result of this was not good, i couldnt access my
    >user
    >RJ> account or root :( Anyway i had to cut the power to my PC since i
    >couldnt
    >RJ> shut it down because i was locked out. After that i went into single
    >user
    >RJ> mode and changed the passwords back and its working now but i cant hide
    >the
    >RJ> passwords. So i guess after all this rambling my question is how to i
    >secure
    >RJ> the password file? How do i change from the encrypted password to *
    >without
    >RJ> screwing over my system? Any help would by much appreciated
    >
    >try doing that:
    >#Forget your root pw?
    >1. Reboot. when you see the "boot" prompt, type boot -s and hit enter
    >2. run this command: fsck -p / && mount -u /
    >3. use the `passwd` command to set a password for root
    >4. reboot, done
    >
    >hope that helps..
    >
    >
    >_______________________________________________
    >freebsd-questions@freebsd.org mailing list
    >http://lists.freebsd.org/mailman/listinfo/freebsd-questions
    >To unsubscribe, send any mail to
    >"freebsd-questions-unsubscribe@freebsd.org"

    _________________________________________________________________
    Find a cheaper internet access deal - choose one to suit you.
    http://www.msn.co.uk/internetaccess

    _______________________________________________
    freebsd-questions@freebsd.org mailing list
    http://lists.freebsd.org/mailman/listinfo/freebsd-questions
    To unsubscribe, send any mail to "freebsd-questions-unsubscribe@freebsd.org"


  • Next message: Hanspeter Roth: "Re: identity using send-pr with dynamic address"

    Relevant Pages

    • RE: master.passwd -- securing
      ... Subject: master.passwd -- securing ... >command to set a password for root 4. ... >To unsubscribe, send any mail to ... Find a cheaper internet access deal - choose one to suit you. ...
      (freebsd-questions)
    • Re: Best way of restoring /etc from backups after fresh install?
      ... # vipw # as root, change uid and gid of your user, then login again as user ... To UNSUBSCRIBE, email to debian-user-REQUEST@xxxxxxxxxxxxxxxx ...
      (Debian-User)
    • RE: Cant reboot after update
      ... Kernel panic-not syncing: VFS: unable to mount root fs on ... server in our server room just after I started a normal reboot, ... etch host running on a Dell PowerEdge 2450 server. ... To UNSUBSCRIBE, email to debian-user-REQUEST@xxxxxxxxxxxxxxxx ...
      (Debian-User)
    • Re: Unable to su as a user, I get: Cannot execute /bin/bash: Permission denied
      ... It'll be executed by the user, not root. ... To UNSUBSCRIBE, email to debian-user-REQUEST@xxxxxxxxxxxxxxxx ... Also to be a right prat, chmod a-x `which chmod` (don't do it, but i've ... Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org ...
      (Debian-User)
    • Re: Unable to su as a user, I get: Cannot execute /bin/bash: Permission denied
      ... sorry..i lost you on that...you think that someone changed the permissions ... It'll be executed by the user, not root. ... To UNSUBSCRIBE, email to debian-user-REQUEST@xxxxxxxxxxxxxxxx ... Also to be a right prat, chmod a-x `which chmod` (don't do it, but i've ...
      (Debian-User)