Re: Listing locked user accounts on Linux
By: Deuce to John Guillory on Wed May 02 2012 06:56 pm
> Re: Listing locked user accounts on Linux
> By: John Guillory to Chris Trainor on Wed May 02 2012 09:18 am
>
> > I often wondered why folks used to make it sound like 'shadowed'
> > passwords
> > where secure, all it looked like they was doing was moving the file to
> > another location.... ;-)
>
> /etc/passwd is readable by all users. The shadow password isn't. When the
> password is placed in the shadow password file, it is secure.
>
We used to sanitize inputs so someone couldn't enter as a user name:
Bill The |cat /ect/passwd
Then it would execute the command after the pipe and cat the password list to
their console. But yes shadowed passwords give an asteris * instead of the
password in that file.
---
■ Synchronet ■ Vertrauen ■ Home of Synchronet ■ telnet://vert.synchro.net
|