strange behaviour when password longer than 512 bytes

Pablo Hinojosa Nava <[email protected]> Fri, 3 Jun 2016 17:43:43 +0200
Newsgroups gmane.linux.pam
Message-ID <CAE9JbX9xz99t=6MpV_gc73tNezuRdDrHg3Ni4eQvVLUrFzy+PA@mail.gmail.com>
--===============8546681745331537106==
Content-Type: multipart/alternative; boundary=089e01419e0290e75e0534619720

--089e01419e0290e75e0534619720
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: quoted-printable

I have seen a strange behaviour when I try to set a password longer than
512 bytes.

I guess because of CVE-2015-3238 the limit of the password was set to 512
bytes. That is why if I set a password of more than 512 bytes only first
512 are saved (maybe in this line
<https://git.fedorahosted.org/cgit/linux-pam.git/tree/modules/pam_unix/pam_=
unix_passwd.c#n313>).
The problem is the remaining characters. Using passwd, the rest of the
characters go outside the command and are interpreted by next command
(usually another prompt). That is why if you set, for example, this
password:

ThisisalooooooooooooongpasswordAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA=
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAABBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBB=
BBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBCCCCCCCCCCCCCCC=
CCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCC=
CCCCCCCCCCDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDD=
DDDDDDDDDDDDDDDDDDDDDDDDqwertyuiopasdfghjklzxcvbnmqwertyuiopasdfghjklzxcvbn=
mqwertyuiopasdfghjklzxcvbnm0123456789012345678901234567890CVEecho
> "Hello"
>

that is, 512 random characters and then echo "Hello", passwd set the
password (only 512 characters) BUT the remaining characters are executed as
a command. So with that password, passwd will update the password and then
execute

echo "Hello"
>


[root@localhost ~]# passwd username
> Changing password for user username.
> New password:
> Retype new password:
> passwd: all authentication tokens updated successfully.
> [root@localhost ~]# echo "Hello"
> Hello
>

Why the remaining characters are executed? Why do not drop them? How can I
manage them to prevent being interpreted by next command?

Cheers,

Pablo Hinojosa.    CC58B86B
<https://pgp.mit.edu/pks/lookup?op=3Dget&search=3D0x947319E2CC58B86B>
PabloHinojosa.is
<http://pablohinojosa.is/this?utm_source=3Dfirma&utm_medium=3Dcorreo&utm_ca=
mpaign=3Dfirma>

--089e01419e0290e75e0534619720
Content-Type: text/html; charset=UTF-8
Content-Transfer-Encoding: quoted-printable

<div dir=3D"ltr"><div class=3D"gmail_quote"><div dir=3D"ltr"><div><div>I ha=
ve seen a strange behaviour when I try to set a password longer than 512 by=
tes.<br></div><br>I guess because of CVE-2015-3238 the limit of the passwor=
d was set to 512 bytes. That is why if I set a password of more than 512 by=
tes only first 512 are saved (<a href=3D"https://git.fedorahosted.org/cgit/=
linux-pam.git/tree/modules/pam_unix/pam_unix_passwd.c#n313" target=3D"_blan=
k">maybe in this line</a>). The problem is the remaining characters. Using =
passwd, the rest of the characters go outside the command and are interpret=
ed by next command (usually another prompt). That is why if you set, for ex=
ample, this password:<br><br><blockquote style=3D"margin:0px 0px 0px 0.8ex;=
border-left:1px solid rgb(204,204,204);padding-left:1ex" class=3D"gmail_quo=
te">ThisisalooooooooooooongpasswordAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA=
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAABBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBB=
BBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBCCCCCCCCCCC=
CCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCC=
CCCCCCCCCCCCCCDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDD=
DDDDDDDDDDDDDDDDDDDDDDDDDDDDqwertyuiopasdfghjklzxcvbnmqwertyuiopasdfghjklzx=
cvbnmqwertyuiopasdfghjklzxcvbnm0123456789012345678901234567890CVEecho &quot=
;Hello&quot;<br></blockquote><br></div><div>that is, 512 random characters =
and then echo &quot;Hello&quot;, passwd set the password (only 512 characte=
rs) BUT the remaining characters are executed as a command. So with that pa=
ssword, passwd will update the password and then execute <br><br></div><div=
><blockquote style=3D"margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(20=
4,204,204);padding-left:1ex" class=3D"gmail_quote">echo &quot;Hello&quot;<b=
r></blockquote><br><br></div><div><blockquote style=3D"margin:0px 0px 0px 0=
.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex" class=3D"gmai=
l_quote">[root@localhost ~]# passwd username<br>Changing password for user =
username.<br>New password: <br>Retype new password: <br>passwd: all authent=
ication tokens updated successfully.<br>[root@localhost ~]# echo &quot;Hell=
o&quot;<br>Hello<br></blockquote><br></div><div>Why the remaining character=
s are executed? Why do not drop them? How can I manage them to prevent bein=
g interpreted by next command?<br></div><div><br></div><div>Cheers, <br></d=
iv><div><br clear=3D"all"><div><div><div dir=3D"ltr"><div>Pablo Hinojosa. =
=C2=A0 =C2=A0<a href=3D"https://pgp.mit.edu/pks/lookup?op=3Dget&amp;search=
=3D0x947319E2CC58B86B" style=3D"font-size:12.8px" target=3D"_blank">CC58B86=
B</a><br><a href=3D"http://pablohinojosa.is/this?utm_source=3Dfirma&amp;utm=
_medium=3Dcorreo&amp;utm_campaign=3Dfirma" target=3D"_blank">PabloHinojosa.=
is</a></div><div><br></div><div><br></div></div></div></div>
</div></div>
</div><br></div>

--089e01419e0290e75e0534619720--


--===============8546681745331537106==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

_______________________________________________
Pam-list mailing list
[email protected]
https://www.redhat.com/mailman/listinfo/pam-list
--===============8546681745331537106==--