RE: Account Lockout in Solaris 8

From: BAUMLER Julie L (julie.x.baumler_at_co.multnomah.or.us)
Date: 10/14/03

  • Next message: Glenn M. Brunette, Jr.: "Re: Account Lockout in Solaris 8"
    To: "'focus-sun@securityfocus.com'" <focus-sun@securityfocus.com>, "'kenneth.l.denski@us.pwc.com'" <kenneth.l.denski@us.pwc.com>
    Date: Tue, 14 Oct 2003 11:33:28 -0700
    
    

    > -----Original Message-----
    > From: Kevin L Prigge [mailto:klp@tc.umn.edu]
    > Sent: Tuesday, October 14, 2003 9:29 AM
    > To: Kenneth Denski
    > Cc: focus-sun@securityfocus.com
    > Subject: Re: Account Lockout in Solaris 8
    >
    >
    > On Tue, Oct 14, 2003 at 04:09:38PM -0000, Kenneth Denski wrote:
    > >
    > >
    > > Does anyone know if it is possible to implement account
    > lockouts in Sun Solaris 8? I want to set it so that after 3
    > bad login attempts, the user is locked out and must be reset
    > by the Admin.
    > >
    > > Is there any way to do this?
    >

    A) Write/port your own PAM module.

    B) Adjust the variables in /etc/default/login to log to syslog after 3 bad
    attempts, have a x(x=relatively long) SLEEPTIME, set retries to 4.
    (Optionally, adjust syslog.conf so these messages go to a log file of their
    own.) Use a log file reading tool (such as swatch or roll your own) to
    check for messages every y(y<x) seconds, parse out the username and issue
    "passwd -l <username>".

    >
    > Make sure they know that there are real DOS possibilities with a
    > scheme such as this, and just because this functionality was available
    > on IBM mainframes, it doesn't make it a good or useful idea.

    Also, in general, password reset proceedures tend to have weaknesses that
    are open to social engineering. How do you verify users in remote
    buildings (or who are traveling)? How do you securely get them their new
    password without being subject to some sort of evesdropping or known
    password attack? If you use the phone what do you do when phone service is
    out for that site? How do you securely reset a password for a deaf user at
    a remote site? How many times would a user have to get locked out in a row
    before you realized that the problem wasn't their inability to type in the
    password you gave them, but someone continuing a password guessing attack?
    What if they ended up at a different help desk tech each time? (Even if
    it's not your plan today, this will eventually cause enough work to get
    turned over to the help desk.)

    Julie

    Julie L Baumler, SCNA
    Sr Systems Administrator
    Multnomah County IT
    503-988-3749 x26909


  • Next message: Glenn M. Brunette, Jr.: "Re: Account Lockout in Solaris 8"

    Relevant Pages

    • Re: password change
      ... Dim objRootDSE, strDNSDomain, strQuery, adoRecordset, strComputer ... ' Open the log file for write access. ... is not reset to a separate text file of "missed" computers. ...
      (microsoft.public.windows.server.general)
    • Re: winsock error
      ... it will remove that malware from your system. ... It has the Winsock reset command built into it. ... That log file will be saved in the same directory you ran the program from, using the email link at the bottom of my page send me a copy of that log file. ...
      (microsoft.public.windowsxp.general)
    • Re: Have static IP address, but tcp/ip property page always shows "Obtain IP address automatically",
      ... That log file will be saved in the same directory you ran the program from, using the email link at the bottom of my page send me a copy of that log file. ... correct static IP address and my connectivity is still fine. ... reset Linkage\UpperBind for PCI ...
      (microsoft.public.windowsxp.basics)
    • Re: Chassis intrusion detected
      ... Contact your Help Desk if you did not personally open your chassis. ... I have went to setup and it askes me for a but my password ... how do i get in to reset the password or reset to clear or reset to no ...
      (microsoft.public.security)
    • AD Permissions Problem
      ... my Help Desk personal have the ability to reset and change user ... What I mean is in credit for example, ... they will be able to reset all the user passwords, except one or two which is ...
      (microsoft.public.windows.server.active_directory)