#961 Webmin login password

1.050
closed
None
5
2003-02-02
2003-02-01
Anonymous
No

If the webmin's user password contains more than
8 characters, then the user is allowed to login by
just typing in the first 8 characters of the
password. All the other characters are ignored.

Example: Password "abcd1234xyz" for user "test".
Typing in only abcde1234 for user test will allow
the user to login to webmin.

This happens if the authentication password is set
in the webmin user configuration. If it is UNIX
authentication then it is not a problem.

dhyanesh@intafrica.com

Discussion

  • Jamie Cameron

    Jamie Cameron - 2003-02-02
    • assigned_to: nobody --> jcameron
    • status: open --> closed
     
  • Jamie Cameron

    Jamie Cameron - 2003-02-02

    Logged In: YES
    user_id=129364

    This is an un-avoidable side effect of the standard Unix
    password encryption method that Webmin uses. To remain
    compatible with passwords in the /etc/shadow file, this
    format has to be used .. but unfortunately, it only takes
    the first 8 characters into account.

     

Log in to post a comment.

Get latest updates about Open Source Projects, Conferences and News.

Sign up for the SourceForge newsletter:





No, thanks