BUG: Partly typed passwords works

Discussion in 'General' started by Salvis, Sep 7, 2007.

  1. Salvis

    Salvis New Member

    Hello!
    I and my clients noticed that - partly typed passwords works for /stats/ directory and for FTP access.
    Example:
    Orginal password: Lainite9449270
    User can log in to ftp and /stats/ directory just typing username and password: Lainite9 can access to his account. this not works for ispconfig login.
    I tried to do something with password: p@55w0rd but unsuccesofully. Somewhere is little bug what allows gain access, but i can't notice where and how to fix it.
     
  2. the_spy

    the_spy New Member

    it's because the maximum password lenght recognized by unix crypt is 8 chars. You can search in the forum I think to see how to use md5 crypt with ispconfig
     

Share This Page