Re: Should I give passwords to server ids?

From: WarpKat (uce@ftc.gov)
Date: 10/15/02


From: WarpKat <uce@ftc.gov>
Date: Tue, 15 Oct 2002 11:55:29 -0700

Sundial Services wrote:

>
> After the aforementioned scare involving the user "news," I began to
> wonder.
>
> There are several user-ids associated with daemons. Some have a shell
> other than /false/ or /nolog/.
>
> What are the passwords to these daemon accounts? Are they predictable?
> Should they be changed? If so, what will break?

The daemons do not have any passwords by default. If someone were to
bruteforce the passwords to the daemons, they could run applications with
the permissions of the server daemons and possibly cause some harm.

The daemon users should never have passwords.



Relevant Pages

  • Re: Should I give passwords to server ids?
    ... > There are several user-ids associated with daemons. ... they have no passwords and you can not log onto those accounts in any normal ...
    (comp.os.linux.security)
  • Should I give passwords to server ids?
    ... After the aforementioned scare involving the user "news," I began to wonder. ... There are several user-ids associated with daemons. ... Some have a shell other ...
    (comp.os.linux.security)
  • Re: PAM and login.conf the login process
    ... specifically with validating the passwords and change passwords. ... PAM and does PAM check the login.conf for certain characteristics and ... login.conf to see if a user meets the minimum password change requirements? ... Or does the login.conf only apply when in shell and not through daemons. ...
    (freebsd-questions)

Quantcast