Re: Pen testing a CVS server

From: Alexandre Carmel-Veilleux (saruman_at_northernhacking.org)
Date: 05/18/03

  • Next message: Royans Tharakan: "RE: Pen testing a CVS server"
    Date: Sun, 18 May 2003 15:20:26 -0400
    To: Bugsy <bugsy9999@yahoo.com>
    
    
    

    On Sun, May 18, 2003 at 07:17:09AM -0700, Bugsy wrote:
    >
    > Checking passwords
    > cvs -d :pserver:root@host.domain.com:/wrong/cvs/root
    > login
    > Tells me if i got the root password right or not.

            Hmm, I've never been in any environement where CVS didn't have it's
    own, separate, password and group files. So this should not yield an actual
    user passwords. Assuming the password is different then the system one.

            I agree that the error messages should be terser in order to leak
    less information, possibly with an n seconds timeout after an error.

    Alex

    
    



  • Next message: Royans Tharakan: "RE: Pen testing a CVS server"

    Relevant Pages

    • Re: [SLE] Root password corrupt?
      ... try logging in as root from the login prompt. ... The thing is, if /bin/su loses its suid bit, it will always tell you the ... The first thing then would be to reset the root password ...
      (SuSE)
    • Signal 1, Name stays on "who" list under Linux
      ... I'm not too sure if this is off topic, it might be a bug in sshd which is ... OpenSSH v3.4p1, SSH protocols 1.5/2.0 ... 1> connect to the linux box via SSH client and login as any user ... To get past step 2 you have to enter root password, ...
      (comp.security.ssh)
    • Re: cleartext passwords get into log files
      ... This is just one of many, many reasons why the system log files in general, ... and the auth failure log in particular (if separate), ... readable by root (or by an admin group who know the root password anyway). ...
      (Bugtraq)
    • Re: [SLE] Root password corrupt?
      ... My boot drive isn't the shared drives, ... I guess 'su' has lost its suid bit. ... > A normal login from the login prompt should still work though, ... The first thing then would be to reset the root password ...
      (SuSE)
    • Re: user reboot/shutdown (was Re: GUI login screen and non-root shutdown...)
      ... >> yesterday, when I reinstalled debian on a laptop, that I couldn?t login as ... > least re-authenticate) to reboot the computer. ... reboot the machine without providing any passwd. ... The login screen still wants the root password if I want to make ...
      (Debian-User)