Re: strange behaviour when password longer than 512 bytes
Brian Mathis <[email protected]> Fri, 3 Jun 2016 15:47:43 -0400
| Newsgroups | gmane.linux.pam |
|---|---|
| Message-ID | <CALKwpEwgYf2OzxGHDY53X7ixRXwQTS3oS6edUF-Ad_TiCxiFyA@mail.gmail.com> |
--===============5477359103907784352== Content-Type: multipart/alternative; boundary=001a114b16d80e3d39053464ff25 --001a114b16d80e3d39053464ff25 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: quoted-printable Any time you paste into a terminal window and a program stops accepting input, the remaining characters are passed to the next shell prompt. This is typical behavior for any situation where you are pasting something from the clipboard, as a paste is really seen by the program as if you are just typing really fast. The passwd program is no longer accepting input after 512 bytes, so you are seeing this behavior. ~ Brian Mathis @orev On Fri, Jun 3, 2016 at 11:43 AM, Pablo Hinojosa Nava <[email protected]> wrote: > I have seen a strange behaviour when I try to set a password longer than > 512 bytes. > > I guess because of CVE-2015-3238 the limit of the password was set to 512 > bytes. That is why if I set a password of more than 512 bytes only first > 512 are saved (maybe in this line > <https://git.fedorahosted.org/cgit/linux-pam.git/tree/modules/pam_unix/pa= m_unix_passwd.c#n313>). > The problem is the remaining characters. Using passwd, the rest of the > characters go outside the command and are interpreted by next command > (usually another prompt). That is why if you set, for example, this > password: > > ThisisalooooooooooooongpasswordAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA= AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAABBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBB= BBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBCCCCCCCCCCCCC= CCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCC= CCCCCCCCCCCCDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDD= DDDDDDDDDDDDDDDDDDDDDDDDDDqwertyuiopasdfghjklzxcvbnmqwertyuiopasdfghjklzxcv= bnmqwertyuiopasdfghjklzxcvbnm0123456789012345678901234567890CVEecho >> "Hello" >> > > that is, 512 random characters and then echo "Hello", passwd set the > password (only 512 characters) BUT the remaining characters are executed = as > a command. So with that password, passwd will update the password and the= n > execute > > echo "Hello" >> > > > [root@localhost ~]# passwd username >> Changing password for user username. >> New password: >> Retype new password: >> passwd: all authentication tokens updated successfully. >> [root@localhost ~]# echo "Hello" >> Hello >> > > Why the remaining characters are executed? Why do not drop them? How can = I > manage them to prevent being interpreted by next command? > > Cheers, > > Pablo Hinojosa. CC58B86B > <https://pgp.mit.edu/pks/lookup?op=3Dget&search=3D0x947319E2CC58B86B> > PabloHinojosa.is > <http://pablohinojosa.is/this?utm_source=3Dfirma&utm_medium=3Dcorreo&utm_= campaign=3Dfirma> > > > > > _______________________________________________ > Pam-list mailing list > [email protected] > https://www.redhat.com/mailman/listinfo/pam-list > --001a114b16d80e3d39053464ff25 Content-Type: text/html; charset=UTF-8 Content-Transfer-Encoding: quoted-printable <div dir=3D"ltr">Any time you paste into a terminal window and a program st= ops accepting input, the remaining characters are passed to the next shell = prompt.=C2=A0 This is typical behavior for any situation where you are past= ing something from the clipboard, as a paste is really seen by the program = as if you are just typing really fast.=C2=A0 The passwd program is no longe= r accepting input after 512 bytes, so you are seeing this behavior.<br><br>= <div><div class=3D"gmail_extra"><br clear=3D"all"><div><div data-smartmail= =3D"gmail_signature"><div dir=3D"ltr"><span><div><div dir=3D"ltr"><div>~ Br= ian Mathis<br></div>@orev<br></div></div></span></div></div></div> <br><br><div class=3D"gmail_quote">On Fri, Jun 3, 2016 at 11:43 AM, Pablo H= inojosa Nava <span dir=3D"ltr"><<a href=3D"mailto:[email protected]" ta= rget=3D"_blank">[email protected]</a>></span> wrote:<br><blockquote cla= ss=3D"gmail_quote" style=3D"margin:0 0 0 .8ex;border-left:1px #ccc solid;pa= dding-left:1ex"><div dir=3D"ltr"><div class=3D"gmail_quote"><div dir=3D"ltr= "><div><div>I have seen a strange behaviour when I try to set a password lo= nger than 512 bytes.<br></div><br>I guess because of CVE-2015-3238 the limi= t of the password was set to 512 bytes. That is why if I set a password of = more than 512 bytes only first 512 are saved (<a href=3D"https://git.fedora= hosted.org/cgit/linux-pam.git/tree/modules/pam_unix/pam_unix_passwd.c#n313"= target=3D"_blank">maybe in this line</a>). The problem is the remaining ch= aracters. Using passwd, the rest of the characters go outside the command a= nd are interpreted by next command (usually another prompt). That is why if= you set, for example, this password:<br><br><blockquote style=3D"margin:0p= x 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex" cl= ass=3D"gmail_quote">ThisisalooooooooooooongpasswordAAAAAAAAAAAAAAAAAAAAAAAA= AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAABBBBBBBBBBBBBBBBBBBB= BBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBB= BBBBBCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCC= CCCCCCCCCCCCCCCCCCCCCCCCCCCCCCDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDD= DDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDqwertyuiopasdfghjklzxcvbnmqwert= yuiopasdfghjklzxcvbnmqwertyuiopasdfghjklzxcvbnm0123456789012345678901234567= 890CVEecho "Hello"<br></blockquote><br></div><div>that is, 512 ra= ndom characters and then echo "Hello", passwd set the password (o= nly 512 characters) BUT the remaining characters are executed as a command.= So with that password, passwd will update the password and then execute <b= r><br></div><div><blockquote style=3D"margin:0px 0px 0px 0.8ex;border-left:= 1px solid rgb(204,204,204);padding-left:1ex" class=3D"gmail_quote">echo &qu= ot;Hello"<br></blockquote><br><br></div><div><blockquote style=3D"marg= in:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1e= x" class=3D"gmail_quote">[root@localhost ~]# passwd username<br>Changing pa= ssword for user username.<br>New password: <br>Retype new password: <br>pas= swd: all authentication tokens updated successfully.<br>[root@localhost ~]#= echo "Hello"<br>Hello<br></blockquote><br></div><div>Why the rem= aining characters are executed? Why do not drop them? How can I manage them= to prevent being interpreted by next command?<br></div><div><br></div><div= >Cheers, <br></div><div><br clear=3D"all"><div><div><div dir=3D"ltr"><div>P= ablo Hinojosa. =C2=A0 =C2=A0<a href=3D"https://pgp.mit.edu/pks/lookup?op=3D= get&search=3D0x947319E2CC58B86B" style=3D"font-size:12.8px" target=3D"_= blank">CC58B86B</a><br><a href=3D"http://pablohinojosa.is/this?utm_source= =3Dfirma&utm_medium=3Dcorreo&utm_campaign=3Dfirma" target=3D"_blank= ">PabloHinojosa.is</a></div><div><br></div><div><br></div></div></div></div= > </div></div> </div><br></div> <br>_______________________________________________<br> Pam-list mailing list<br> <a href=3D"mailto:[email protected]" target=3D"_blank">[email protected]= m</a><br> <a href=3D"https://www.redhat.com/mailman/listinfo/pam-list" rel=3D"norefer= rer" target=3D"_blank">https://www.redhat.com/mailman/listinfo/pam-list</a>= <br></blockquote></div><br></div></div></div> --001a114b16d80e3d39053464ff25-- --===============5477359103907784352== Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Content-Disposition: inline _______________________________________________ Pam-list mailing list [email protected] https://www.redhat.com/mailman/listinfo/pam-list --===============5477359103907784352==--