Re: Shadow Passwords
| From: | Paul Meagher | Date: | Sun, 16 Dec 2001 19:18:43 +0000 |
| Subject: | Re: Shadow Passwords | ||
| References: | 1 | Groups: | php.pear.dev |
| Request: | Send a blank email to pear-dev+get-3496@lists.php.net to get a copy of this message | ||
To answer my own question, to authenticate against a Shadow password file,
you need to modify the File_Passwd class to use MD5 encryption instead of
standard DES encryption.
To invoke MD5 from the crypt function you need to give it a 12 character
salt instead of a 2 character salt.
Just change this:
crypt($pass,substr($this->users[$user],0,2))
To this:
crypt($pass,substr($this->users[$user],0,12))
Perhaps there should be a switch variable in the File_Passwd class that
allows you to set the encryption standard you want to use. It would have
the effect of setting the salt length passed into the crypt function. Or
maybe it is just not worth handling this case as the there are some nasty
security issues involved in reading a shadow password file (which is NOT
supposed to be world readable).
Regards,
Paul Meagher
----- Original Message -----
From: "Paul Meagher" <paul@datavore.com>
To: <pear-dev@lists.php.net>
Sent: Saturday, December 15, 2001 2:19 PM
Subject: [PEAR-DEV] Shadow Passwords
> I was attempting to use the File_Passwd class developed by Rasmus to
> authenticate against a shadow password file.
>
> It doesn't appear to work. The password I read from the file and the
> encrypted version of the user supplied password are different suggesting
> that shadow password files might use a different encryption function? Or
> maybe I'm doing something wrong here...
>
> The shadow password read from the file:
>
> $1$0pZjv6IT$lfRwC6m5vMU8XGLkfrU.v/
>
> The encrypted password generated using the user supplied password and
this
> function - crypt($pass,substr($this->users[$user],0,2));
>
> $1$$zXMQxpKDH91klGV8Q0Jnn
>
> I needed to change the permissions on the shadow password file (world
> readable) to access it using a web based php script. I was just doing
this
> to test the class to see if it could actually authenticate against a
shadow
> file. I am testing this on a Slackware Linux 8.0 platform.
>
> As an aside, is there any way to have a web based php script access the
> shadow file in a way that is more secure than having to change the
> permissions on the shadow file to world readable?
>
> Regards,
> Paul Meagher
>
>
>
>
>
>
> --
> PEAR Development Mailing List (http://pear.php.net/)
> To unsubscribe, e-mail: pear-dev-unsubscribe@lists.php.net
> For additional commands, e-mail: pear-dev-help@lists.php.net
> To contact the list administrators, e-mail: php-list-admin@lists.php.net
>
>