Mailinglist Archive: opensuse (3351 mails)

< Previous Next >
Re: [opensuse] Root's password
  • From: James Knott <james.knott@xxxxxxxxxx>
  • Date: Mon, 19 Mar 2007 13:05:37 -0400
  • Message-id: <45FEC2E1.1040908@xxxxxxxxxx>
Dave Cotton wrote:
On Mon, 2007-03-19 at 12:42 -0400, James Knott wrote:
Dave Cotton wrote:
On Mon, 2007-03-19 at 10:00 -0400, James Knott wrote:
Enter the passwd command. You will then be prompted for the old password etc.
Are you sure?


Yes.

The please type passwd when logged in as root and see what happens,
because you will not be asked for the old password.

see below

/home/dave # passwd
Changing password for root.
New Password: Reenter New Password: Password changed.

Sure now?

Curious. It asks for the old password, when changing as a user, but not when as root. That means that if someone finds an open root session, they can change the password!

--
To unsubscribe, e-mail: opensuse+unsubscribe@xxxxxxxxxxxx
For additional commands, e-mail: opensuse+help@xxxxxxxxxxxx

< Previous Next >