Re: Possible Hacking routine

thoth@purplefrog.com
Fri, 11 Jul 1997 11:34:38 -0400

Robert Hiltibidal <rob@rob.fgi.net> ,in message <Pine.LNX.3.96.970711053124.303
3B-100000@rob.fgi.net>, wrote:

>
> Howdy,
>
> Got a question... Does the portmaster log failed telnet attempts to the
> radius files? If it doesn't by default is there some way it could be
> coaxed into logging failed attempts? Basically what we want is to log the
> failed attempt, the username and ip the attempt came from and to really
> give us that warm fuzzy feeling we'd like to log the username and
> passwords used.

If you log the passwords you will get incorrect passwords for normal users
accounts, from which it would be a small brute-force space to guess the
correct password. If you have a couple of failed passwords in the logs, it
might even be easy to hand-guess the correct password.

If you log the failed usernames, you might also get passwords. This was
pointed out on a security list.

-- 
Bob Forsman                                   thoth@gainesville.fl.us
           http://www.gainesville.fl.us/~thoth/