Date: Sun, 27 Oct 2013 23:00:49 +0100 From: Patrick Proniewski <patpro@patpro.net> To: Liste FreeBSD-security <freebsd-security@freebsd.org> Cc: des@des.no, Andrei <az@azsupport.com> Subject: Re: OpenPAM/SSHD privacy hole (FreeBSD 9.2+ affected) Message-ID: <EE68A65B-660F-480B-88E6-73E7D1C8359F@patpro.net> In-Reply-To: <20131027225016.3cdab10e@azsupport.com> References: <20131023135408.38752099@azsupport.com> <1382529986.729788.498652166.90148.2@c-st.net> <86y55emw8a.fsf@nine.des.no> <20131027195755.00b0cb2c@azsupport.com> <86txg2mm9n.fsf@nine.des.no> <20131027225016.3cdab10e@azsupport.com>
next in thread | previous in thread | raw e-mail | index | archive | help
[-- Attachment #1 --]
On 27 oct. 2013, at 22:50, Andrei wrote:
> On Sun, 27 Oct 2013 22:33:56 +0100
> Dag-Erling Smrgrav <des@des.no> wrote:
>
>> Andrei <az@azsupport.com> writes:
>>> In /etc/pam.d/sshd from:
>>> auth required pam_unix.so no_warn
>>> try_first_pass to:
>>> auth required pam_unix.so no_warn try_first_pass authtok_prompt
>>>
>>> Right?
>>
>> auth required pam_unix.so no_warn try_first_pass
>> authtok_prompt="Password:"
>>
>> BTW, I recently noticed that try_first_pass doesn't work as documented
>> (and hasn't for ten years), but I haven't had time to fix it yet.
>
> You might be surprised, but authtok_prompt="Password:" have same results as
> just authtok_prompt. Empty screen and no "Password:" prompt.
> FreeBSD 9.2 tested.
Same here (9.2-RELEASE amd64), whatever I put for authtok_prompt.
The end of a verbose attempt reads:
debug3: authmethod_lookup keyboard-interactive
debug3: remaining preferred: password
debug3: authmethod_is_enabled keyboard-interactive
debug1: Next authentication method: keyboard-interactive
debug2: userauth_kbdint
debug2: we sent a keyboard-interactive packet, wait for reply
debug2: input_userauth_info_req
debug2: input_userauth_info_req: num_prompts 1
and then, nothing.
patpro
[-- Attachment #2 --]
0 *H
010 + 0 *H
]0!0 y0
*H
010 UIL10U
StartCom Ltd.1+0)U"Secure Digital Certificate Signing1806U/StartCom Class 1 Primary Intermediate Client CA0
130919164736Z
140920203230Z0>10Upatpro@patpro.net1 0 *H
patpro@patpro.net0"0
*H
0
4*Ύ1wN.-ߴ'm|p?;j}/{ni"7ns\aOS5kꗝPcrq/oܕ+-CYd"-R,HO<uHᢶdq{
OEŖ!WFyKqLZti/̇}d}gl
WjglGyp8li2~Adw-b(vg8b^`*:l> 00 U0 0U0U%0++0Uq7gW UQ$H`z0U#0Sr풜\|~5NԸQ0U0patpro@patpro.net0LU C0?0;+70*0.+"http://www.startssl.com/policy.pdf0+00' StartCom Certification Authority0This certificate was issued according to the Class 1 Validation requirements of the StartCom CA policy, reliance only for the intended purpose in compliance of the relying party obligations.06U/0-0+)'%http://crl.startssl.com/crtu1-crl.crl0+009+0-http://ocsp.startssl.com/sub/class1/client/ca0B+06http://aia.startssl.com/certs/sub.class1.client.ca.crt0#U0http://www.startssl.com/0
*H
?q
h/4ӓ[ۆAGn"fD%'9\yL9J繆lUL<
5N}HE*p~Ddfs~:4)tk7No>|%|G{P?szXgOd]D%*zaZ=?3u<vl@5EwB+Dϻ#+|;d;UwIw%r+c!@FaX0400
*H
0}10 UIL10U
StartCom Ltd.1+0)U"Secure Digital Certificate Signing1)0'U StartCom Certification Authority0
071024210155Z
171024210155Z010 UIL10U
StartCom Ltd.1+0)U"Secure Digital Certificate Signing1806U/StartCom Class 1 Primary Intermediate Client CA0"0
*H
0
-).2AUGo#G
B|NDRpM-B=o-we5JQpa>O.#._<V
[~**pz~3WG .ᘟMlr[<Ce6fqO"uxfWN#uicgkv$Lb%y`_{`xK'GN 00U00U0USr풜\|~5NԸQ0U#0N@[i04hCA0f+Z0X0'+0http://ocsp.startssl.com/ca0-+0!http://www.startssl.com/sfsca.crt0[UT0R0'%#!http://www.startssl.com/sfsca.crl0'%#!http://crl.startssl.com/sfsca.crl0U y0w0u+70f0.+"http://www.startssl.com/policy.pdf04+(http://www.startssl.com/intermediate.pdf0
*H
}x,\c^#wMq}>UK/^yX֏y frMIŲB61ymQҨݬZ0&