Re: UNIX Password change from Windows.
Posted in 1996
Mike Aubury wrote: > > so here is a script that DOES work... > -------------------------------------------------------------- > # this file is called pass2 > echo "$1 > $2 > $2" | rsh localhost passwd > -------------------------------------------------------------- > datax line: > pass2 "{Old Password}" "{New Password}" > > -- > Mike Aubury _\\?/_ OK, being a paranoid systems admin on caffiene.... IMHO one should not use a script for this for the following reasons: 1) It is up to the application to verify that the user typed in the password correctly. 2) You do not verify the password against the /etc/passwd or its shadow (if it exists) [or even yppasswd if they are running NIS] 3) Some wiley hacker can see your script and figure out a way to subterfuge it. 4) Your script will always return true, even if the password didn't change. 5) rsh requires that you run this command from a "trusted" host. 6) You have to have Informix call this function from a stored proceedure or from some form of application partitioning. You have to be the user to to change your passwd. [Remember the original poster said that the app is running on windows and not on unix.] So does anyone know the UID of a proc executing a shell script? A good rule of thumb is to never use a shell script when dealing with a security issue. Write a C code program which uses the setuid function and use the appropriate function calls to get the correct UID, PASSWORD, Username. Also you can use the standard crypt function. [Should be fast enough.] When you compile your C code, remember to set the sticky bit of the executable and to make sure it is owned by root. Then change the protection of the source code to 600 . -Mike PS. "Safety is no accident."