kinit sending clear text password
melissa_benkyo
wyl_lyf at yahoo.com
Wed Apr 21 08:59:17 EDT 2004
william.fiveash at Sun.COM (Will Fiveash) wrote in message news:<20040420215158.GF627194 at sun.com>...
> On Tue, Apr 20, 2004 at 01:09:53PM -0700, melissa_benkyo wrote:
> > hello folks,
> >
> > thanks for all the help. I wouldn't have make it here so far without
> > your help. :) thanks. Now I'm trying to use pam api's instead but the
> > thing is pam_krb5 seems to be sending the password in clear text then
> > I tried to use kinit <username> and I was shocked to see the password.
> > (Am I a good hacker or what?) hehehe is it supposed to be like this?
>
> No. First check the docs for using pam_krb5 and GSS-API on
> <http://docs.sun.com> and make sure your program isn't buggy. If that
> isn't the case try pkgchk to see if your binaries have been modified.
> If that isn't the case, file a bug with Sun.
>
> BTW, how did you "see" the password?
I'm just using the kinit that comes from sun I'm not programming yet
by seeing I meant being able to see the typed in password when I
snooped or used ethereal.
r-xr-xr-x 1 root bin 15768 Sep 8 2003 /usr/bin/kinit
More information about the Kerberos
mailing list