From owner-freebsd-security Mon Nov 1 6:26: 9 1999 Delivered-To: freebsd-security@freebsd.org Received: from baga.unet.ru (baga.unet.ru [195.9.254.56]) by hub.freebsd.org (Postfix) with ESMTP id 7FAB214A06 for ; Mon, 1 Nov 1999 06:25:57 -0800 (PST) (envelope-from vick@unet.ru) Received: from unet.ru (baga.unet.ru [195.9.254.56]) by baga.unet.ru (8.9.3/Unet) with ESMTP id RAA07606 for ; Mon, 1 Nov 1999 17:25:54 +0300 (MSK) (envelope-from vick@unet.ru) Message-ID: <381DA2F1.5CA8A8D@unet.ru> Date: Mon, 01 Nov 1999 17:25:54 +0300 From: VicTor Ponomarev Organization: LPI & Unet Ltd. X-Mailer: Mozilla 4.61 [en] (X11; I; FreeBSD 3.3-UNET i386) X-Accept-Language: en MIME-Version: 1.0 To: security@freebsd.org Subject: PAM and security hole in 3.3 stable Content-Type: text/plain; charset=us-ascii Content-Transfer-Encoding: 7bit Sender: owner-freebsd-security@FreeBSD.ORG Precedence: bulk X-Loop: FreeBSD.org Comment line login auth required pam_unix.so try_first_pas in pam.conf and you can login from any terminal without password. It seems that pam_cleartext_pass_ok.so library opens a security hole to the box. Bye, Vick. To Unsubscribe: send mail to majordomo@FreeBSD.org with "unsubscribe freebsd-security" in the body of the message