Generatig Encrypted smbpasswd file

SATOH Fumiyasu fumiya at cij.co.jp
Tue May 11 03:36:53 GMT 1999


Peter Galbavy <Peter.Galbavy at knowledge.com> wrote:
>I have always, in my ignorance of the protocols, wonder this; on a
>setup where the passwords are only checked against the smbpasswd file
>and not "transmitted" to any other servers etc, is it not possible to
>support a backdoor use of the UNIX crypt format ? Even if it is down
>to using the crypt()'ed string as the password for samba and then just
>doing final, local comparisons.

If you can replace crypt() function in library, you can redirect
plain text password to SMB server by using RedCrypt:

    http://wing-yee.ntc.keio.ac.jp/hosokawa/redcrypt/

-- >8 -- signature -- >8 --
FROM    : SATOH Fumiyasu <fumiya at cij.co.jp>
WEB     : http://www.bento.ad.jp/~fumiya/
WEB(LAN): http://kumasun.si.ykhm.cij.co.jp/
SAMBA   : http://samba.bento.ad.jp/


More information about the samba-technical mailing list