Security Basics mailing list archives

Re: remote passwd change


From: cc <cc () belfordhk com>
Date: Fri, 03 Oct 2003 11:22:28 +0800

Ruiz Cifuentes, Rolando Matias (CL - Santiago) wrote:


telnet myserver anyport (using a .bat file in their computers)

and then the server replies something like:

Enter your Username: <user>
Enter your OldPass: <pass1>
Enter your NewPass: <pass2>
Enter your NewPass again: <pass2>
Your password has been change. Have a nice day!

I've been trying to do this for eons and still haven't
figured it out.  As with non-linux users, they won't/
don't understand why they need to telnet to a server.

I thought about using a secured web form installed on
the company's server and accessible only to LAN users;
but couldn't figure out how to get the perl script/
php script to actually change the passwords since
the UID/GID of the Apache server isn't root-based
(which is the correct way of doing things).

I did find something like chpass on the net, but
couldn't figure out how to get it running.

The only way, right now that i can think of, is
to teach the users the benefit of your solution. (Making
sure, of course that the telnet port is only
accessible to LAN IPs.)

If someone out there has any good ideas, I'm also
willing to try.





---------------------------------------------------------------------------
----------------------------------------------------------------------------


Current thread: