Root login without password backdoor

Discuss problems installing or using TrackStudio.

Root login without password backdoor

Postby victor » Thu Nov 20, 2003 4:49 pm

Hello,

I have detected a problem: I can login like root without write a password (if I write a wrong password I cant login).

I tried modifing the root name (Admin) to check if this could be that LDAP has a Admin user registered with password null.
I tried if I can login like other user without write a password.

None of this trials worked. I only have found the root without password backdoor.

Thanks
Víctor J. Tomás
Computer Engineer
victor
 
Posts: 253
Joined: Tue Sep 23, 2003 11:03 pm
Location: Bs.As, Argentina

Re: Root login without password backdoor

Postby admin » Thu Nov 20, 2003 5:11 pm

victor wrote:Hello,

I have detected a problem: I can login like root without write a password (if I write a wrong password I cant login).

I tried modifing the root name (Admin) to check if this could be that LDAP has a Admin user registered with password null.
I tried if I can login like other user without write a password.

None of this trials worked. I only have found the root without password backdoor.

Thanks


Just check it with hosted service - all works fine for me. Please send me debug logs by e-mail
Maxim Kramarenko (mailto: maximkr@trackstudio.com)
TrackStudio - Hierarchical Bug & Issue Tracking Software
http://www.trackstudio.com
admin
Site Admin
 
Posts: 7454
Joined: Thu Jan 01, 1970 3:00 am
Location: Smolensk, Russia

Postby mvasenkov » Thu Nov 20, 2003 5:17 pm

Very strange situation. I can't login in to my own test instance without a password.
TrackStudio wrote all logon process information into log (without passwords). Can you please send this information to Maxim?
Skype (RU): max.vasenkov
Email/Jabber: max.vasenkov@gmail.com
twitter: @winzard
mvasenkov
TrackStudio Support
 
Posts: 365
Joined: Tue Jan 14, 2003 5:57 pm
Location: Smolensk

Postby victor » Thu Nov 20, 2003 6:52 pm

mvasenkov wrote:Very strange situation. I can't login in to my own test instance without a password.
TrackStudio wrote all logon process information into log (without passwords). Can you please send this information to Maxim?


I checked the log I dont found nothing abnormal...

I commented to Maxim that I found a problem using LDAP:

If I try to login like a user that is not registered in LDAP and I dont write a password TS leave me login.
Víctor J. Tomás
Computer Engineer
victor
 
Posts: 253
Joined: Tue Sep 23, 2003 11:03 pm
Location: Bs.As, Argentina

Postby admin » Thu Nov 20, 2003 7:30 pm

victor wrote:
mvasenkov wrote:Very strange situation. I can't login in to my own test instance without a password.
TrackStudio wrote all logon process information into log (without passwords). Can you please send this information to Maxim?


I checked the log I dont found nothing abnormal...

I commented to Maxim that I found a problem using LDAP:

If I try to login like a user that is not registered in LDAP and I dont write a password TS leave me login.


OK, we'll check and fix this bug ASAP.
Maxim Kramarenko (mailto: maximkr@trackstudio.com)
TrackStudio - Hierarchical Bug & Issue Tracking Software
http://www.trackstudio.com
admin
Site Admin
 
Posts: 7454
Joined: Thu Jan 01, 1970 3:00 am
Location: Smolensk, Russia

Postby victor » Thu Nov 20, 2003 7:34 pm

admin wrote:OK, we'll check and fix this bug ASAP.


Thanks,

But I dont know yet if this is a TS bug or a problem with our ActiveDirectory/LDAP: maybe you are receiving an 'user-not-found' indication from LDAP and this joined to the null password do that TS run in bug, OR maybe our LDAP is telling to TS 'ok-all-is-fine' when an unknown user with a null password is queried, I dont know.
Víctor J. Tomás
Computer Engineer
victor
 
Posts: 253
Joined: Tue Sep 23, 2003 11:03 pm
Location: Bs.As, Argentina

Postby admin » Thu Nov 20, 2003 7:37 pm

victor wrote:
admin wrote:OK, we'll check and fix this bug ASAP.


Thanks,

But I dont know yet if this is a TS bug or a problem with our ActiveDirectory/LDAP: maybe you are receiving an 'user-not-found' indication from LDAP and this joined to the null password do that TS run in bug, OR maybe our LDAP is telling to TS 'ok-all-is-fine' when an unknown user with a null password is queried, I dont know.


I think that this can be bug with library that we use to work with LDAP. I already have strange situation when I click "Test connection" and they report that all OK, but requested IP even not exists in network.
Maxim Kramarenko (mailto: maximkr@trackstudio.com)
TrackStudio - Hierarchical Bug & Issue Tracking Software
http://www.trackstudio.com
admin
Site Admin
 
Posts: 7454
Joined: Thu Jan 01, 1970 3:00 am
Location: Smolensk, Russia

Postby victor » Thu Nov 20, 2003 7:40 pm

I think that we could take a short way trying to reproduce my problem over a confiable LDAP installation (my installation is ActiveDirectory/LDAP and poorly administrated).
Víctor J. Tomás
Computer Engineer
victor
 
Posts: 253
Joined: Tue Sep 23, 2003 11:03 pm
Location: Bs.As, Argentina

Postby victor » Mon Nov 24, 2003 3:23 pm

Hello,

Have you reproduced the problem?

Any solution?

Thanks,
Víctor J. Tomás
Computer Engineer
victor
 
Posts: 253
Joined: Tue Sep 23, 2003 11:03 pm
Location: Bs.As, Argentina

Postby admin » Mon Nov 24, 2003 4:51 pm

victor wrote:Hello,

Have you reproduced the problem?

Any solution?

Thanks,


This problem still in process, sorry.
Maxim Kramarenko (mailto: maximkr@trackstudio.com)
TrackStudio - Hierarchical Bug & Issue Tracking Software
http://www.trackstudio.com
admin
Site Admin
 
Posts: 7454
Joined: Thu Jan 01, 1970 3:00 am
Location: Smolensk, Russia

Next

Return to TrackStudio Support

Who is online

Users browsing this forum: No registered users and 1 guest