Skip site navigation (1)Skip section navigation (2)
Date:      Mon, 27 Aug 2001 02:59:16 -0500
From:      "default" <default013subscriptions@hotmail.com>
To:        "Colin Percival" <cperciva@sfu.ca>, <freebsd-questions@freebsd.org>, <freebsd-security@freebsd.org>
Subject:   Re: Logins without full password!
Message-ID:  <OE46l4rhYQYx3G5aYY600004a32@hotmail.com>
References:  <5.0.0.25.1.20010827004910.0306cfc8@popserver.sfu.ca>

next in thread | previous in thread | raw e-mail | index | archive | help
Doh, ... hmmm there must be some reason why they installed it that way ...
are there any compatability issues with MD5? ...

How would one change over from DES to MD5? (withoug having to re-install)

Thanks for your help,

Jordan

----- Original Message -----
From: "Colin Percival" <cperciva@sfu.ca>
To: "default" <default013subscriptions@hotmail.com>
Sent: Monday, August 27, 2001 2:51 AM
Subject: Re: Logins without full password!


>    Sounds like you're using DES-encrypted passwords.  This is much weaker
> than MD5 encryption, and as you've noticed, only uses the first 8
> characters of a password.
>
> http://www.freebsd.org/doc/en_US.ISO8859-1/books/handbook/crypt.html
>
> At 02:15 AM 8/27/2001 -0500, you wrote:
> >Hi,
> >
> >I just noticed that on one of my FreeBSD machines, one is able to login
via
> >any means by typing in only the first 8 or so characters of the password.
> >You can also type the first 8 characters and anything else after that,
for
> >example if the password were password, one could type: 'passwordxxxxxxx'
and
> >be able to login!
> >
> >I'm not too worried as this is only a test machine that I keep on my
> >internal network, however, I would like to know how it works...
> >
> >Is this normal? How does one disable this?
> >
> >Thanks,
> >
> >Jordan
> >
> >To Unsubscribe: send mail to majordomo@FreeBSD.org
> >with "unsubscribe freebsd-security" in the body of the message
>
>

To Unsubscribe: send mail to majordomo@FreeBSD.org
with "unsubscribe freebsd-questions" in the body of the message




Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?OE46l4rhYQYx3G5aYY600004a32>