<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
	<channel>
		<atom:link href="http://dev1galaxy.org/extern.php?action=feed&amp;tid=4937&amp;type=rss" rel="self" type="application/rss+xml" />
		<title><![CDATA[Dev1 Galaxy Forum / Secure /etc/passwd ?]]></title>
		<link>http://dev1galaxy.org/viewtopic.php?id=4937</link>
		<description><![CDATA[The most recent posts in Secure /etc/passwd ?.]]></description>
		<lastBuildDate>Sat, 12 Mar 2022 14:32:14 +0000</lastBuildDate>
		<generator>FluxBB</generator>
		<item>
			<title><![CDATA[Re: Secure /etc/passwd ?]]></title>
			<link>http://dev1galaxy.org/viewtopic.php?pid=35168#p35168</link>
			<description><![CDATA[<p>I think alpinelinux has a way of hiding users in /etc/passwd. Im not on alpine at the moment but from memory last time i looked my user was called &quot;linux user&quot; in /etc/passwd but user name aka <span class="bbc">/home/username</span> was hevidevi. Ill have to revisit alpine again to understand more.</p><p>Edit to add. Alpine linux was absent the shadow file/package from base install afaik.</p>]]></description>
			<author><![CDATA[dummy@example.com (hevidevi)]]></author>
			<pubDate>Sat, 12 Mar 2022 14:32:14 +0000</pubDate>
			<guid>http://dev1galaxy.org/viewtopic.php?pid=35168#p35168</guid>
		</item>
		<item>
			<title><![CDATA[Re: Secure /etc/passwd ?]]></title>
			<link>http://dev1galaxy.org/viewtopic.php?pid=35157#p35157</link>
			<description><![CDATA[<p>Thank you HOAS,</p><p>I knew that the actual password are stored in <strong>/etc/shadow</strong>.</p><p>But I found curious that any user account can list the full list of user registered on the machine..</p>]]></description>
			<author><![CDATA[dummy@example.com (SpongeBOB)]]></author>
			<pubDate>Fri, 11 Mar 2022 14:25:17 +0000</pubDate>
			<guid>http://dev1galaxy.org/viewtopic.php?pid=35157#p35157</guid>
		</item>
		<item>
			<title><![CDATA[Re: Secure /etc/passwd ?]]></title>
			<link>http://dev1galaxy.org/viewtopic.php?pid=35152#p35152</link>
			<description><![CDATA[<div class="quotebox"><cite>SpongeBOB wrote:</cite><blockquote><div><p>Is it not insecure that Others have read permissions ?</p></div></blockquote></div><p>No. The actual passwords are encrypted and stored under /etc/shadow as per <a href="https://manpages.debian.org/bullseye/passwd/passwd.5.en.html" rel="nofollow">passwd(5)</a>.</p><div class="quotebox"><cite>SpongeBOB wrote:</cite><blockquote><div><p>I change it to 640</p></div></blockquote></div><p>Change it back. Many utilities use that file to map user IDs to user names. It should be world-readable.</p><p>EDIT: use <a href="https://manpages.debian.org/bullseye/passwd/pwck.8.en.html" rel="nofollow">pwck(8)</a> &amp; <a href="https://manpages.debian.org/bullseye/passwd/grpck.8.en.html" rel="nofollow">grpck(8)</a> to verify the integrity and validity of /etc/passwd,/etc/shadow &amp; /etc/group.</p>]]></description>
			<author><![CDATA[dummy@example.com (Head_on_a_Stick)]]></author>
			<pubDate>Fri, 11 Mar 2022 09:08:09 +0000</pubDate>
			<guid>http://dev1galaxy.org/viewtopic.php?pid=35152#p35152</guid>
		</item>
		<item>
			<title><![CDATA[Secure /etc/passwd ?]]></title>
			<link>http://dev1galaxy.org/viewtopic.php?pid=35151#p35151</link>
			<description><![CDATA[<p>Hi everyone,</p><p>I see that by default the file <strong>/etc/passwd</strong> is 64<strong>4</strong></p><p>Is it not insecure that Others have read permissions ? I&#039;m not feeling comfortable with that...</p><p>I change it to 640 but of course when I log-in with a user that start <strong>startxfce4</strong> it&#039;s won&#039;t launch the GUI and stay in CLI...</p><p>I would like to give the correct ACL permissions to make xcfe start, but I don&#039;t even know witch account should have read acces ??</p><p>Thanks</p>]]></description>
			<author><![CDATA[dummy@example.com (SpongeBOB)]]></author>
			<pubDate>Fri, 11 Mar 2022 08:36:23 +0000</pubDate>
			<guid>http://dev1galaxy.org/viewtopic.php?pid=35151#p35151</guid>
		</item>
	</channel>
</rss>
