I don't know if this is normal, but the thing is, let's say I have a Solaris user called gloaiza and its password is password2getin
I'm logging into the server with PuTTY, I just put 192.168.224.100 and it prompts a windows asking for an user, so I type gloaiza, then it asks for a password and let's say I type password2geti by mistake, and it worked! I'm IN the server!
Is that normal? It also works if I put something like password2getin2.
I'm not a native English speaker, so, in case there's something you can't understand please ask me
OS: Oracle Solaris 10 1/13
passwork
get you in?pass2word
, then it works withpass2wor
,pass2word1
,pass2worr1
, and so on... I think it works with everything once you typepass2wor
I don't think it is a big problem, but isn't good either.busybox
will silently fall back to DES if you don't have all the right crypto options enabled in its.config
and yourlibc
. Maybe take a minute today to double-check yourpasswd
/shadow
files? ;)