Password on telnet: only first characters required!

Post new topic   Reply to topic    DD-WRT Forum Index -> Broadcom SoC based Hardware
Author Message
ro-maniak
DD-WRT User


Joined: 07 Jun 2006
Posts: 367

PostPosted: Tue Jun 27, 2006 8:38    Post subject: Password on telnet: only first characters required! Reply with quote
I've noticed a bug: I use a rather longish password (about 16 characters, alphanumeric, caps/noncaps). When going into the router over the web interface, I have to input the whole password (doh, this is correct behaviour).

But when I telnet in, it also let's me get in with only the first about 10 characters! Embarassed Shocked

I've checked: those 10 first characters have to be the correct ones, otherwise you cannot get in. But anything you type after those (nothing or some thrash) does not matter. I am sorry but I have not checked so far what the exact number of characters is that is enough.

I am using DDWRT54GL, Firmware: DD-WRT v23 SP1 Final (05/30/06) mini.

_________________
If you use DD-WRT, you HAVE to make a donation! See this topic too: http://www.dd-wrt.com/phpBB2/viewtopic.php?t=228
Sponsor
Eko
DD-WRT Developer/Maintainer


Joined: 07 Jun 2006
Posts: 5771

PostPosted: Tue Jun 27, 2006 9:02    Post subject: Reply with quote
Bugtracker: #725, #1276
ro-maniak
DD-WRT User


Joined: 07 Jun 2006
Posts: 367

PostPosted: Tue Jun 27, 2006 9:46    Post subject: Reply with quote
Ah sorry, I do not have access to the bugtracker. Embarassed
_________________
If you use DD-WRT, you HAVE to make a donation! See this topic too: http://www.dd-wrt.com/phpBB2/viewtopic.php?t=228
Eko
DD-WRT Developer/Maintainer


Joined: 07 Jun 2006
Posts: 5771

PostPosted: Tue Jun 27, 2006 9:59    Post subject: Reply with quote
"
telnet and ssh uses the cypt() UNIX password. crypt() uses up to eight characters, any extra characters are discarded. There's nothing we can do about it.

The web server uses the nvram parameter "http_passwd" in clear text. This is why it is uses all characters.
"
ro-maniak
DD-WRT User


Joined: 07 Jun 2006
Posts: 367

PostPosted: Tue Jun 27, 2006 10:15    Post subject: Reply with quote
I see... that may be a good caveat to put up somewhere in the wiki, because this means that you will not only have to make sure that your password as a whole is secure (good mix in alpha/numeric/caps/noncaps characters), but also (!) that the first 8 characters are on themselves secure enough!

Rolling Eyes Shocked

_________________
If you use DD-WRT, you HAVE to make a donation! See this topic too: http://www.dd-wrt.com/phpBB2/viewtopic.php?t=228
rkramer
DD-WRT User


Joined: 07 Jun 2006
Posts: 71

PostPosted: Tue Jun 27, 2006 12:01    Post subject: Reply with quote
that has been around since the early days in linux. I would seriously evaluate if you want telnet open to the internet though, or even enabled.
netsigi
DD-WRT Novice


Joined: 17 Jun 2006
Posts: 13

PostPosted: Mon Jul 17, 2006 15:29    Post subject: Reply with quote
What abaut the SALT mechanism? Is it implemented with crypt?
BrainSlayer
Site Admin


Joined: 06 Jun 2006
Posts: 7492
Location: Dresden, Germany

PostPosted: Mon Jul 17, 2006 15:31    Post subject: Reply with quote
yes it is
_________________
"So you tried to use the computer and it started smoking? Sounds like a Mac to me.." - Louis Rossmann https://www.youtube.com/watch?v=eL_5YDRWqGE&t=60s
Display posts from previous:    Page 1 of 1
Post new topic   Reply to topic    DD-WRT Forum Index -> Broadcom SoC based Hardware All times are GMT

Navigation

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You can attach files in this forum
You can download files in this forum