IceWalkers.com - Linux Software downloads and news
Name : Password :
Linux SoftwareLinux RPMLinux HowtosLink UsAboutAdvertise

Linux Shadow Password HOWTO

Search Howtos :Match :
Next Previous Contents

3. Getting the Shadow Suite.

3.1 History of the Shadow Suite for Linux

DO NOT USE THE PACKAGES IN THIS SECTION, THEY HAVE SECURITY PROBLEMS

The original Shadow Suite was written by John F. Haugh II.

There are several versions that have been used on Linux systems:

  • shadow-3.3.1 is the original.
  • shadow-3.3.1-2 is Linux specific patch made by Florian La Roche <flla at stud.uni-sb.de> and contains some further enhancements.
  • shadow-mk was specifically packaged for Linux.

The shadow-mk package contains the shadow-3.3.1 package distributed by John F. Haugh II with the shadow-3.3.1-2 patch installed, a few fixes made by Mohan Kokal <magnus at texas.net> that make installation a lot easier, a patch by Joseph R.M. Zbiciak for login1.c (login.secure) that eliminates the -f, -h security holes in /bin/login, and some other miscellaneous patches.

The shadow.mk package was the previously recommended package, but should be replaced due to a security problem with the login program.

There are security problems with Shadow versions 3.3.1, 3.3.1-2, and shadow-mk involving the login program. This login bug involves not checking the length of a login name. This causes the buffer to overflow causing crashes or worse. It has been rumored that this buffer overflow can allow someone with an account on the system to use this bug and the shared libraries to gain root access. I won't discuss exactly how this is possible because there are a lot of Linux systems that are affected, but systems with these Shadow Suites installed, and most pre-ELF distributions without the Shadow Suite are vulnerable!

For more information on this and other Linux security issues, see the Linux Security home page (Shared Libraries and login Program Vulnerability)

3.2 Where to get the Shadow Suite.

The only recommended Shadow Suite is still in BETA testing, however the latest versions are safe in a production environment and don't contain a vulnerable login program.

The package uses the following naming convention:

shadow-YYMMDD.tar.gz
where YYMMDD is the issue date of the Suite.

This version will eventually be Version 3.3.3 when it is released from Beta testing, and is maintained by Marek Michalkiewicz <marekm at i17linuxb.ists.pwr.wroc.pl>. It's available as: shadow-current.tar.gz.

The following mirror sites have also been established:

You should use the currently available version.

You should NOT use a version older than shadow-960129 as they also have the login security problem discussed above.

When this document refers to the Shadow Suite I am referring to the this package. It is assumed that this is the package that you are using.

For reference, I used shadow-960129 to make these installation instructions.

If you were previously using shadow-mk, you should upgrade to this version and rebuild everything that you originally compiled.

3.3 What is included with the Shadow Suite.

The Shadow Suite contains replacement programs for:

su, login, passwd, newgrp, chfn, chsh, and id

The package also contains the new programs:

chage, newusers, dpasswd, gpasswd, useradd, userdel, usermod, groupadd, groupdel, groupmod, groups, pwck, grpck, lastlog, pwconv, and pwunconv

Additionally, the library: libshadow.a is included for writing and/or compiling programs that need to access user passwords.

Also, manual pages for the programs are also included.

There is also a configuration file for the login program which will be installed as /etc/login.defs.


Next Previous Contents
Search Howtos :Match :
My Money 2.0.49
Personal financial software
Linux Kernel 2.6 2.6.32-rc8
Linux Kernel
GCstar 1.5.0
Personal collections manager
ImageMagick 6.5.7.9
ImageMagick image processing studio
BibleTime 2.4
Bible study software for Linux / KDE
PHP 5.3.1
Server-side, cross-platform, HTML embedded scripting language.
LFTP 4.0.4
Shell-like command line ftp client.
Tellico 2.1.1
Collection manager for books, music, videos, and bibliographies
Totem 2.28.4
Movie player for Gnome
GNOME 2.29.2
GNOME desktop environment
Free IT Magazines, White Papers, eBooks, and more !
Oracle Magazine

Contains technology strategy articles, sample code, tips, Oracle and partner news, how to articles for developers and DBAs, and more.

Vulnerability Management for Dummies

Get all the Facts and See How to Implement a Successful Vulnerability Management Program.

Website Magazine

Has tapped premier talent in the Internet industry for our content and each and every issue will contain practical advice and insights for website owners.

Linux Software Map
Find Linux RPM
Best Rated Linux Software
Most Rated Linux Software
Linux Distributions
Linux Howtos
Quick Survey

Please take our survey and help us improve our website to serve you better.

Thank you.
Linux Software
Linux / IT Resources
Site Resources
Google
Privacy Policy
Contact Us
Submit Software
Advertising info