[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: Linux and Security



On Wed, 19 Aug 1998, Joey Hess wrote:

> No, it's not reversable. There is no way to get the original password from
> the data in the shadow password file.
> 
> Login simply takes the password the user enters, encrypts it using crypt(), 
> and compares it with that's in the password file. No decryption is done.

Correct. So you are still stuck with a brute-force attack.


George Bonser

The Linux "We're never going out of business" sale at an FTP site near you!


Reply to: