View previous topic :: View next topic |
Author |
Message |
mike_c Tux's lil' helper
![Tux's lil' helper Tux's lil' helper](/images/ranks/rank_rect_1.gif)
![](images/avatars/gallery/Simpsons/simpsons_groundskeeper_will.gif)
Joined: 09 Dec 2003 Posts: 76
|
Posted: Fri Dec 31, 2004 12:47 am Post subject: set root password blank? |
|
|
how can i set roots password to be blank
everytime i try i get that annoying "password is WAY to short" message
i know this is insecure, but i dont really care
thanks
Mike |
|
Back to top |
|
![](templates/gentoo/images/spacer.gif) |
Pithlit l33t
![l33t l33t](/images/ranks/rank_rect_4.gif)
![](images/avatars/1267572538425de909443e2.jpg)
Joined: 27 Dec 2003 Posts: 887 Location: fuhen
|
Posted: Fri Dec 31, 2004 12:54 am Post subject: |
|
|
Not only it's insecure but it's incredibly stupid... I think your system is trying to save you from yourself...
Code: | root@machina pithlit # passwd
New UNIX password:
BAD PASSWORD: it's WAY too short
Retype new UNIX password:
No password supplied
No password supplied
No password supplied
passwd: Authentication token manipulation error
root@machina pithlit #
|
I tried it anyway... ![Razz :P](images/smiles/icon_razz.gif) |
|
Back to top |
|
![](templates/gentoo/images/spacer.gif) |
mike_c Tux's lil' helper
![Tux's lil' helper Tux's lil' helper](/images/ranks/rank_rect_1.gif)
![](images/avatars/gallery/Simpsons/simpsons_groundskeeper_will.gif)
Joined: 09 Dec 2003 Posts: 76
|
Posted: Fri Dec 31, 2004 12:56 am Post subject: |
|
|
why is it stupid?
This is for a box that doesnt don't run sshd or other external login inservices.
And I don't think anyone i live with has an interest in screwing aroung on my computer |
|
Back to top |
|
![](templates/gentoo/images/spacer.gif) |
Pithlit l33t
![l33t l33t](/images/ranks/rank_rect_4.gif)
![](images/avatars/1267572538425de909443e2.jpg)
Joined: 27 Dec 2003 Posts: 887 Location: fuhen
|
Posted: Fri Dec 31, 2004 1:01 am Post subject: |
|
|
They don't need to be screwing with it. Someone could just sit on the keyboard and by some weird coincidence delete everything. If someone would intend to screw with your comp (with physical access) no root pass would save you anyway. |
|
Back to top |
|
![](templates/gentoo/images/spacer.gif) |
mike_c Tux's lil' helper
![Tux's lil' helper Tux's lil' helper](/images/ranks/rank_rect_1.gif)
![](images/avatars/gallery/Simpsons/simpsons_groundskeeper_will.gif)
Joined: 09 Dec 2003 Posts: 76
|
Posted: Fri Dec 31, 2004 1:09 am Post subject: |
|
|
oh well
the probabllity of that happening is not worth having to type a password all the time
i found what i needed in the passwd manpage anyway
if anyone else is interested in it, try this
|
|
Back to top |
|
![](templates/gentoo/images/spacer.gif) |
Ateo Advocate
![Advocate Advocate](/images/ranks/rank-G-1-advocate.gif)
Joined: 02 Jun 2003 Posts: 2022 Location: Vegas Baby!
|
Posted: Fri Dec 31, 2004 1:44 am Post subject: |
|
|
There's a time and a place for a passwordless root account. A perfect example is a test environment of any kind. Just because you don't understand the reason's is no reason to assume it's stupid. |
|
Back to top |
|
![](templates/gentoo/images/spacer.gif) |
loki99 Advocate
![Advocate Advocate](/images/ranks/rank-G-1-advocate.gif)
![](images/avatars/840039902431febc0a0f2b.jpg)
Joined: 10 Oct 2003 Posts: 2056 Location: Vienna, €urope
|
Posted: Fri Dec 31, 2004 1:53 am Post subject: |
|
|
mike_c wrote: | why is it stupid?
|
you are far from having a secure box by just setting a root password. but without one you are asking for trouble! it is just the same as all those windoze-boxes that are not patched, have no firewall and AV.
that kind of behavior is a risk to all of us! ![Rolling Eyes :roll:](images/smiles/icon_rolleyes.gif) |
|
Back to top |
|
![](templates/gentoo/images/spacer.gif) |
Pithlit l33t
![l33t l33t](/images/ranks/rank_rect_4.gif)
![](images/avatars/1267572538425de909443e2.jpg)
Joined: 27 Dec 2003 Posts: 887 Location: fuhen
|
Posted: Fri Dec 31, 2004 2:13 am Post subject: |
|
|
I'm perfectly aware of that Ateo. But if you need a passwordless root account for testing reasons I assume you know how to get one.
And "just because I'm to lazy to type a password everytime I need root access" isn't what I'd call a good reason. I may be wrong tho. And no offense to anyone. I'm just assuming without any facts (altho I've seen this type of reasons).
I still say it's stupid. ![Embarassed :oops:](images/smiles/icon_redface.gif) |
|
Back to top |
|
![](templates/gentoo/images/spacer.gif) |
mike_c Tux's lil' helper
![Tux's lil' helper Tux's lil' helper](/images/ranks/rank_rect_1.gif)
![](images/avatars/gallery/Simpsons/simpsons_groundskeeper_will.gif)
Joined: 09 Dec 2003 Posts: 76
|
Posted: Fri Dec 31, 2004 2:37 am Post subject: |
|
|
i said i dont care in the slighest bit about the security of my system in my first post
bearing that in mind, i dont see how its stupid
i dont deny that its lazy |
|
Back to top |
|
![](templates/gentoo/images/spacer.gif) |
kimchi_sg Advocate
![Advocate Advocate](/images/ranks/rank-G-1-advocate.gif)
Joined: 26 Nov 2004 Posts: 3038
|
Posted: Fri Dec 31, 2004 3:39 am Post subject: |
|
|
mike_c wrote: | i dont care in the slighest bit about the security of my system |
You are not ever, ever going to connect your system to the Net, are you?
If you will hook your system to the Net, you'll have to thank a lot other Netizens for not thinking in the same way as you. |
|
Back to top |
|
![](templates/gentoo/images/spacer.gif) |
Coz Tux's lil' helper
![Tux's lil' helper Tux's lil' helper](/images/ranks/rank_rect_1.gif)
Joined: 18 Mar 2004 Posts: 99 Location: You wanna stalk me? :p Dominican republic
|
Posted: Fri Dec 31, 2004 4:45 pm Post subject: |
|
|
I think is stupid because I have been rooted before XD It's not a nice experience to have to reinstall your system coz you left a root terminal unused :p
You know, maybe people aren't targeting at YOU they just want to get into someone's machine. I remember some distro that had empty root password by default but I don't remember which.
All the security stuff could sound like crap if you have nothing to hide, but remember that all the time you spent tweaking your system, installing and emerging will go to waste if you get rooted.
The only way I would ever try to do that is if my computer was never going to be connected to the internet and that I have that computer for my personal use, and if I have a much better computer that everybody will want to use, so they don't mess with that one. And I bet that still that way I would have a root pass, at least 'a' XD _________________ Ask smart questions and follow the guidelines to get your post answered|Answer a unanswered post! |
|
Back to top |
|
![](templates/gentoo/images/spacer.gif) |
kimchi_sg Advocate
![Advocate Advocate](/images/ranks/rank-G-1-advocate.gif)
Joined: 26 Nov 2004 Posts: 3038
|
Posted: Fri Dec 31, 2004 4:46 pm Post subject: |
|
|
Coz wrote: | I remember some distro that had empty root password by default but I don't remember which. |
You're probably thinking of Linspire (formerly Lindows). |
|
Back to top |
|
![](templates/gentoo/images/spacer.gif) |
pjp Administrator
![Administrator Administrator](/images/ranks/rank-admin.gif)
![](images/avatars/1154772887439692d88303b.jpg)
Joined: 16 Apr 2002 Posts: 20589
|
Posted: Fri Dec 31, 2004 5:55 pm Post subject: |
|
|
Lets stop the debate about root not having a password. The user explained they were aware of its security risks.
Moved from Installing Gentoo. _________________ Quis separabit? Quo animo? |
|
Back to top |
|
![](templates/gentoo/images/spacer.gif) |
Raffi l33t
![l33t l33t](/images/ranks/rank_rect_4.gif)
![](images/avatars/128099062840d0bd3e528e8.gif)
Joined: 17 Mar 2003 Posts: 731 Location: Moscow, Id.
|
Posted: Fri Dec 31, 2004 8:13 pm Post subject: |
|
|
Stupid or not (and I do think it is stupid). You can simply edit the /etc/shadow file and remove everything between the first two :s. Some applications may still not let you login. |
|
Back to top |
|
![](templates/gentoo/images/spacer.gif) |
aspenhydrowave n00b
![n00b n00b](/images/ranks/rank_rect_0.gif)
Joined: 08 Dec 2004 Posts: 41
|
Posted: Sat Jan 08, 2005 3:42 am Post subject: |
|
|
Raffi wrote: | Stupid or not (and I do think it is stupid). You can simply edit the /etc/shadow file and remove everything between the first two :s. Some applications may still not let you login. |
So supposing I set up a small, cheap machine with no network connectivity to use as a DVD player. Maybe this box has no keyboard at all, and is set up to automatically play a DVD that's inserted. No root password makes a lot of sense here, since I wouldn't be able to type it in anyway. |
|
Back to top |
|
![](templates/gentoo/images/spacer.gif) |
mike_c Tux's lil' helper
![Tux's lil' helper Tux's lil' helper](/images/ranks/rank_rect_1.gif)
![](images/avatars/gallery/Simpsons/simpsons_groundskeeper_will.gif)
Joined: 09 Dec 2003 Posts: 76
|
Posted: Sat Jan 08, 2005 5:56 pm Post subject: |
|
|
I still dont understand how its insecure
If I am not running any external login service, how can anyone take advantage of a lack of root password?
Mike |
|
Back to top |
|
![](templates/gentoo/images/spacer.gif) |
Pithlit l33t
![l33t l33t](/images/ranks/rank_rect_4.gif)
![](images/avatars/1267572538425de909443e2.jpg)
Joined: 27 Dec 2003 Posts: 887 Location: fuhen
|
Posted: Sat Jan 08, 2005 6:14 pm Post subject: |
|
|
You may argue this is a very unlikely scenario but hey... you wondered...
Get online, get hit by a simple virus that does # rm -rf , cry your heart out.
The only box that has a chance of not having a root password in my home would be
1 - a test box (connected to the net),
2 - a honeypot of some sort
3 - a box that is never, ever gonna get a net access
That said I'd prolly still put root passes on them. Simple ones like 'root' or 'pass'. Sides... it's not like I need root access every day. But hey, it's your box. You can do what you want with it. In fact... anyone with access to it (even through malicious html code) can do what they want with it. ...And I'm doing what I shouldn't be doing - ranting. If you think you're safe by doing this then by all means go for it. Most of us (who say it's insecure and stupid) just wanna make sure you know the possible consequences. |
|
Back to top |
|
![](templates/gentoo/images/spacer.gif) |
|