Blank password works for root

Bevan C. Bennett bevan at fulcrummicro.com
Fri Jan 9 01:28:53 UTC 2004


Bill Beeman wrote:
> I just discovered that I can log into my FC1 box as root with either the
> root password, or by simply leaving the password blank!
> 
> Functions this way from a command line, or in a terminal within either
> KDE or Gnome.

What exactly are you doing to 'log in'?
Is this with 'su' from an existing command line, from the system 
console, or with a remote access program like ssh, telnet or rlogin?

If possible, see if the behavior is consistant between using su after 
logging in as a non-root user, logging in on console, or connecting with 
ssh?

The first place I'd look in this case is in /etc/pam.d/
See if there are any files named *.rpmnew and if so check out the 
differences between them and the originals. Look especially to see if 
anything has pam_rootok.so listed, and where.





More information about the fedora-list mailing list