"Administrator password" readable in cleartext on Breezy

Ask a Question related to Ubuntu, Design and Development.

  1. #1

    Default "Administrator password" readable in cleartext on Breezy

    Hi everyone,

    I am new to this news group. But I just stumbled across something at
    htttp://www.dig.com.

    For Ubuntu Breezy you can see the password of the default user, that was
    supplied during the installation.

    Bugreport:
    [url]https://launchpad.net/distros/ubuntu/+bug/34606[/url]

    or
    Ubuntu Forums:
    [url]http://www.ubuntuforums.org/showthread.php?t=143334[/url]

    sorry, to bring bad news. I still love ubuntu :)

    But better fix this in your systems.

    Greetings,
    Alex
    Alexander Koch Guest

  2. Similar Questions and Discussions

    1. Change user role from "Publisher" to "Administrator"
      Have three users on a particular website - all need to be "administrators". Two are listed as administrators (one of which is me), the third is...
    2. "Access Denied" after password change
      Hi all, Users on our Win2003 SBS domain lose their network permissions after being prompted to change their domain password. "Lose" is perhaps...
    3. Could I set TextMode = "Password" ind Editing-Mode of the DataGrid?
      Hello Folks. I have a DataGrid displaying the conten of a SQL-Database. In this table exist a Field wich contains Passwords. Firstly I´d liked to...
    4. #25101 [Opn->Bgs]: (only on .php files)I Keep getting "Enter Network password" popup window
      ID: 25101 Updated by: sniper@php.net Reported By: oc34 at hotmail dot com -Status: Open +Status: ...
    5. problems with getNetText("http://username:password@mydomain.com/mypath/myfile.htm")
      Yes, it should work. No, it won't. You could use the secureNet xtra from http://www.integrationnewmedia.com/ or I think the xtranet xtra will work...
  3. #2

    Default Re: "Administrator password" readable in cleartext on Breezy

    On Mon, 13 Mar 2006 00:29:28 +0100, Alexander Koch wrote:
    > Hi everyone,
    >
    > I am new to this news group. But I just stumbled across something at
    > htttp://www.dig.com.
    >
    > For Ubuntu Breezy you can see the password of the default user, that was
    > supplied during the installation.
    >
    > Bugreport:
    > [url]https://launchpad.net/distros/ubuntu/+bug/34606[/url]
    >
    > or
    > Ubuntu Forums:
    > [url]http://www.ubuntuforums.org/showthread.php?t=143334[/url]
    >
    > sorry, to bring bad news. I still love ubuntu :)
    >
    > But better fix this in your systems.
    >
    > Greetings,
    > Alex
    I saw this on OSNews a few minutes ago and checked through my logs.
    Default user password was not displayed so this does not apply to
    every install for some reason.

    Wayne
    --
    Registered Linux user #375994
    [url]http://www.geocities.jp/rondonko/[/url]

    Wayne Guest

  4. #3

    Default Re: "Administrator password" readable in cleartext on Breezy

    -----BEGIN PGP SIGNED MESSAGE-----
    Hash: SHA1

    On 2006-03-12, Wayne <rondonjin@yahoo.com> wrote:
    > On Mon, 13 Mar 2006 00:29:28 +0100, Alexander Koch wrote:
    >
    >> Hi everyone,
    >>
    >> I am new to this news group. But I just stumbled across something at
    >> htttp://www.dig.com.
    >>
    >> For Ubuntu Breezy you can see the password of the default user, that was
    >> supplied during the installation.
    >>
    >> Bugreport:
    >> [url]https://launchpad.net/distros/ubuntu/+bug/34606[/url]
    >>
    >> or
    >> Ubuntu Forums:
    >> [url]http://www.ubuntuforums.org/showthread.php?t=143334[/url]
    >>
    >> sorry, to bring bad news. I still love ubuntu :)
    >>
    >> But better fix this in your systems.
    >>
    >> Greetings,
    >> Alex
    >
    > I saw this on OSNews a few minutes ago and checked through my logs.
    > Default user password was not displayed so this does not apply to
    > every install for some reason.
    >
    > Wayne
    Wow. Thanks for the info. My password was in clear text! Yikes.

    Eric

    -----BEGIN PGP SIGNATURE-----
    Version: GnuPG v1.4.1 (GNU/Linux)

    iD8DBQFEFLXHcLztWWU+V+oRAjyKAJ4vNhPLYknlpYu4APMcn5 Fgmg0RowCfYN9b
    CzqD4UQMh4FAIC0iEWmrOrk=
    =ZkBd
    -----END PGP SIGNATURE-----
    Eric Meyers Guest

  5. #4

    Default Re: "Administrator password" readable in cleartext on Breezy

    On Mon, 13 Mar 2006 00:29:28 +0100, Alexander Koch wrote:

    A patch has already been submitted so be sure you update your systems.

    sudo apt-get update
    sudo apt-get upgrade

    --
    Chuck

    Chuck Guest

  6. #5

    Default Re: "Administrator password" readable in cleartext on Breezy

    Alexander Koch schrieb:
    > For Ubuntu Breezy you can see the password of the default user, that was
    > supplied during the installation.
    >
    > Bugreport:
    > [url]https://launchpad.net/distros/ubuntu/+bug/34606[/url]
    Thanks for the information. Although I cannot confirm this here on my
    installation, I posted about the problem in my university's newsgroups and
    I'm waiting for the feedback of other users here.

    The problem, while critical, seems to be easily resolved by editing the
    occurences of the password in the logfiles. Does anyone know oif it is
    safe to simply delete the log file(s)? I suspect this might interfere with
    the update process from Breezy to Dapper...

    Jürgen
    Juergen Starek Guest

  7. #6

    Default Re: "Administrator password" readable in cleartext on Breezy

    Juergen Starek <quiterigorouslyfilteredusenetaccount@gmx.de> wrote:
    > Alexander Koch schrieb:
    >
    >> For Ubuntu Breezy you can see the password of the default user, that was
    >> supplied during the installation.
    >>
    >> Bugreport:
    >> [url]https://launchpad.net/distros/ubuntu/+bug/34606[/url]
    >
    > Thanks for the information. Although I cannot confirm this here on my
    > installation, I posted about the problem in my university's newsgroups
    > and
    > I'm waiting for the feedback of other users here.
    >
    > The problem, while critical, seems to be easily resolved by editing the
    > occurences of the password in the logfiles. Does anyone know oif it is
    > safe to simply delete the log file(s)? I suspect this might interfere
    > with
    > the update process from Breezy to Dapper...
    Worry not - deleting the file is fine.

    However, if you suspect/know that any user has ever connected/logged-in to
    the machine then you may be best advised to alter the password from the
    install value as well. uihm yeah and change the root pw too if that's
    enabled.

    --
    William Tasso
    William Tasso Guest

Posting Permissions

  • You may not post new threads
  • You may post replies
  • You may not post attachments
  • You may not edit your posts

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130 131 132 133 134 135 136 137 138 139