Probably a security hole in F13?

Joachim Backes joachim.backes at rhrk.uni-kl.de
Fri Apr 23 07:41:11 UTC 2010


Hi,

I want to report some weird F13 behaviour:

Booting into runlevel 3 (with RHGB, appending ' 3' after RHGB). After 
boot is completed, goto on console #1.

0. Waiting some seconds
1. Very often, when typing the username, it is *not echoed* (but accepted)
2a. In this case, typing in the password, it is fully reflected :-(

------ this appears on console #1 -----------------
Fedora release 13 (Goddard)
Kernel 2.6.33.2-57.fc13.i686 on an i686 (tty1)

eule login: Password: testuser

[testuser at eule ~]$
------------------------  OR case 2b, username is reflected ---- 
---------------------------- and password is reflected ---------
Fedora release 13 (Goddard)
Kernel 2.6.33.2-57.fc13.i686 on an i686 (tty1)

eule login: testuser
Password:testuser
Last login: Thu Apr ........... from localhost.localdomain
------------------------------------------------------------



But: If booting into runlevel 3 *without RHGB*, or into runlevel 5, the 
described effect does not appear.

Anybode made similar experiences?

-- 
Joachim Backes <joachim.backes at rhrk.uni-kl.de>

http://www.rhrk.uni-kl.de/~backes

-------------- next part --------------
A non-text attachment was scrubbed...
Name: smime.p7s
Type: application/pkcs7-signature
Size: 6131 bytes
Desc: S/MIME Cryptographic Signature
Url : http://lists.fedoraproject.org/pipermail/test/attachments/20100423/0eadeb9e/attachment.bin 


More information about the test mailing list