Re: Shadow Passwords

From: Date: Sun, 16 Dec 2001 19:18:43 +0000
Subject: Re: Shadow Passwords
References: 1  Groups: php.pear.dev 
Request: Send a blank email to pear-dev+get-3496@lists.php.net to get a copy of this message
To answer my own question, to authenticate against a Shadow password file, you need to modify the File_Passwd class to use MD5 encryption instead of standard DES encryption. To invoke MD5 from the crypt function you need to give it a 12 character salt instead of a 2 character salt. Just change this: crypt($pass,substr($this->users[$user],0,2)) To this: crypt($pass,substr($this->users[$user],0,12)) Perhaps there should be a switch variable in the File_Passwd class that allows you to set the encryption standard you want to use. It would have the effect of setting the salt length passed into the crypt function. Or maybe it is just not worth handling this case as the there are some nasty security issues involved in reading a shadow password file (which is NOT supposed to be world readable). Regards, Paul Meagher ----- Original Message ----- From: "Paul Meagher" <paul@datavore.com> To: <pear-dev@lists.php.net> Sent: Saturday, December 15, 2001 2:19 PM Subject: [PEAR-DEV] Shadow Passwords > I was attempting to use the File_Passwd class developed by Rasmus to > authenticate against a shadow password file. > > It doesn't appear to work. The password I read from the file and the > encrypted version of the user supplied password are different suggesting > that shadow password files might use a different encryption function? Or > maybe I'm doing something wrong here... > > The shadow password read from the file: > > $1$0pZjv6IT$lfRwC6m5vMU8XGLkfrU.v/ > > The encrypted password generated using the user supplied password and this > function - crypt($pass,substr($this->users[$user],0,2)); > > $1$$zXMQxpKDH91klGV8Q0Jnn > > I needed to change the permissions on the shadow password file (world > readable) to access it using a web based php script. I was just doing this > to test the class to see if it could actually authenticate against a shadow > file. I am testing this on a Slackware Linux 8.0 platform. > > As an aside, is there any way to have a web based php script access the > shadow file in a way that is more secure than having to change the > permissions on the shadow file to world readable? > > Regards, > Paul Meagher > > > > > > > -- > PEAR Development Mailing List (http://pear.php.net/) > To unsubscribe, e-mail: pear-dev-unsubscribe@lists.php.net > For additional commands, e-mail: pear-dev-help@lists.php.net > To contact the list administrators, e-mail: php-list-admin@lists.php.net > >

« previous php.pear.dev (#3496) next »