Shadow Passwords

From: Date: Sat, 15 Dec 2001 18:19:56 +0000
Subject: Shadow Passwords
Groups: php.pear.dev 
Request: Send a blank email to pear-dev+get-3494@lists.php.net to get a copy of this message
I was attempting to use the File_Passwd class developed by Rasmus to authenticate against a shadow password file. It doesn't appear to work. The password I read from the file and the encrypted version of the user supplied password are different suggesting that shadow password files might use a different encryption function? Or maybe I'm doing something wrong here... The shadow password read from the file: $1$0pZjv6IT$lfRwC6m5vMU8XGLkfrU.v/ The encrypted password generated using the user supplied password and this function - crypt($pass,substr($this->users[$user],0,2)); $1$$zXMQxpKDH91klGV8Q0Jnn I needed to change the permissions on the shadow password file (world readable) to access it using a web based php script. I was just doing this to test the class to see if it could actually authenticate against a shadow file. I am testing this on a Slackware Linux 8.0 platform. As an aside, is there any way to have a web based php script access the shadow file in a way that is more secure than having to change the permissions on the shadow file to world readable? Regards, Paul Meagher

« previous php.pear.dev (#3494) next »