[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

[cobalt-users] [Mips] Are these Passwords Shadowed?



Hi list,
After reading BugTraq and finding someone clowned the S&P servers for
not having shadowed passwords, I decided to look at a newly restored
Qube2 from a newly ordered CD and hence ask 2 questions:

1) Are these passwords shadowed?

root:9E8yTJJJJJfdW:0:0:Root:/root:/bin/sh <changed some for protection>
admin:9E8yTJJJJJfdW:110:100:Administrator:/home/users/admin:/bin/bash
 
mitch:liOxtX5H2YOsW:112:100:mitch:/home/users/mitch:/bin/bash
rex:Wn16.op40v16A:113:100:rex:/home/users/rex:/bin/bash
joy:1FilpFx4DqBt.:114:100:joy:/home/users/joy:/bin/bash
"passwd" [readonly] 30 lines, 1311 characters

2) If not, how does one go to shadow them.  I can not find a /etc/shadow
file, and the /etc/passwd has these permissions:

-rw-r--r--   1 root     root         1311 Dec  1 04:04 passwd

which means all users can read the file, disputing a claim made earlier
by Geoff Baysinger <lists@xxxxxxxxxxxxxx> stating that there is "/etc/shadow
in the Qube2". Not here buddy, off a 2 month old CD.