Nmap Security Scanner
*Intro
*Ref Guide
*Install Guide
*Download
*Changelog
*Book
*Docs
Security Lists
*Nmap Hackers
*Nmap Dev
*Bugtraq
*Full Disclosure
*Pen Test
*Basics
*More
Security Tools
*Pass crackers
*Sniffers
*Vuln Scanners
*Web scanners
*Wireless
*Exploitation
*Packet crafters
*More
Site News
Site Search:
Exploit World
Advertising
About/Contact
Credits
Sponsors:
edgeos



Vulnerability Development: Re: vlock bug ? (fwd)

Re: vlock bug ? (fwd)

From: C.J. Oster <lordvadr_at_POBOX.COM>
Date: Thu, 18 Nov 1999 23:53:08 -0600

I've looked into this, and I get the same results. If you read the man
page, either user's password, or root's password will unlock the terminal.
Perhapse the "root's password" is just a reminder that you can also enter
root's password to unlock it. I only have vlock-1.2, because I don't use
it much and never have upgraded it, and I can only get root's password to
work if I set the mode suid root, otherwise root's password won't unlock
it.

--------------------------------------
[lordvadr ~]$ vlock
This TTY is now locked.
Use Alt-function keys to switch to other virtual consoles.
Please enter the password to unlock.
lordvadr's Password: [ lordvadr's password ]

[lordvadr ~]$ vlock
This TTY is now locked.
Use Alt-function keys to switch to other virtual consoles.
Please enter the password to unlock.
lordvadr's Password: [ root's password ]
root's Password: [ root's password ]
 *** That password is incorrect; please try again. ***
....
[lordvadr ~]$ su -c "chmod 4755 /usr/bin/vlock"
...
[lordvadr ~]$ vlock
This TTY is now locked.
Use Alt-function keys to switch to other virtual consoles.
Please enter the password to unlock.
lordvadr's Password: [ anything but lordvadr's password ]
root's Password: [ root's password ]
[lordvadr ~]$
-------------------

-CJO-

On Thu, 18 Nov 1999, m4rcyS wrote:

>Plz take a look at these 2 posts below and try this by yourself.
>
>I'm using RH6.1 (vlock-1.3-2) and definitely I'm NOT using the same
>password for root and marcys :)
>
>
>---------- Forwarded message ----------
>Date: Wed, 17 Nov 1999 10:44:51 -0500
>From: Michael K. Johnson <johnsonm_at_redhat.com>
>To: m4rcyS <marcys_at_free.com.pl>
>Cc: Michael K. Johnson <johnsonm_at_redhat.com>
>Subject: Re: vlock bug ?
>
>
>I am unable to reproduce this. I can't imagine what could possibly
>cause it, either, other than using the same password for root and
>for marcys, which I presume you are not doing...
>
>michaelkjohnson
>
>"Magazines all too frequently lead to books and should be regarded by the
> prudent as the heavy petting of literature." -- Fran Lebowitz
> Linux Application Development http://people.redhat.com/johnsonm/lad/
>
>
>m4rcyS writes:
>>
>>hi,
>>
>>Plz take a look at this:
>>
>>[>>[marcys_at_pentium marcys]$ vlock
>>This TTY is now locked.
>>Use Alt-function keys to switch to other virtual consoles.
>>Please enter the password to unlock.
>>marcys's Password: [invalid passwd typed here]
>>root's Password: [valid MARCYS's passwd typed]
>>[>>[marcys_at_pentium marcys]$
>>
>>Shouldn't vlock accept root's passwd except marcys's passwd?
>>
>>
>>greetz,
>>____________________________________________________________
>> m4rcyS
>>
>> email: marcys_at_free.com.pl, m_at_sh.pl
>>
>>"I think there is a world market for maybe five computers."
>> - Thomas Watson, chairman of IBM, 1943
>>------------------------------------------------------------
>>
>
>

                   C.J. Oster (Linux Guru/Surge Addict)
   ----------------------------------------------------------------------
          Network Security Manager Unix System Administrator
             For BHNet, Bromley Hall WSG, CCSO
          Hoover and Associates University of Illinios
          support_at_bromleygroup.com Office: L538, DCL
          security_at_bromleygroup.com (217)265-8427
   ----------------------------------------------------------------------
   108 E. Healy St, #6
   Champaign, IL 61820
   (217)378-4223
   (580)761-6393

         PGP: 87D5 4216 43A1 42D6 754D 8F5E 24B3 992A B7A1 F556
        "Linux, for people with an IQ above 98" - Bumper Sticker
  "Hm, a little big for a cup holder... Why does it say '4x' on it?"
Received on Nov 19 1999

[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]
edgeos