Whose bright(stupid) idea was this?

From: Dave Millen (postmaster_at_[127.0.0.1)
Date: 11/22/03


Date: Sat, 22 Nov 2003 01:26:34 +0000


For security reasons, I have long been using a usernames similar to:

Mr6xO0g3

(i.e. a totally random mix of upper/lower case and numeric) as the only
permitted ssh logins to systems that I administer. I feel that this along
with similarly sensible passwords, changed frequently, gives added
security against dictionary attacks etc.

Today, I did a completely fresh install of RH 9 on a firewall/gateway
machine, rather than an upgrade. Guess what - I can now only use lowercase
and numerals for usernames. Why not go the whole hog; disregard security
altogether and ignore case, as whinedoze does.

I'll put the old passwd and shadow files back on it tomorrow and see if
they are accepted, but I am shocked at what I consider a retrograde step.

This is the first fresh install I have done for some time. Have I missed a
trick somewhere? Is this a RH peculiarity or is it now 'generic' linux
practice to limit usernames in this way?

Regards,
Dave



Relevant Pages

  • [NEWS] Watchguard Firebox PPTP VPN User Enumeration Vulnerability
    ... Get your security news from a reliable source. ... The PPTP VPN service offered by Watchguard Firebox allows valid usernames ... The PPTP VPN service uses MS-CHAPv2 for authentication. ... engineering attacks, as knowledge of valid usernames may allow an attacker ...
    (Securiteam)
  • Re: password cracker for PCAnywhere and VNC (RFB 003.008)
    ... Do *not* forget to try passwords equal to usernames. ... Does anyone know of good username/password lists for dictionary attack? ... "Discover the Security Benefits of Cisco NetFlow" ... Download FREE Whitepaper "Role of Network Behavior Analysis and Response ...
    (Pen-Test)
  • Re: Username Vulnerability???
    ... Windows, Security, local, security ... > We have recently experienced massive account lockouts. ... Is there a similar vulnerability in Server ... > Somone obviously has a list of our usernames and is using them to try and ...
    (microsoft.public.security)
  • Re: Domain Logon
    ... Probably not what you had in mind, but tokens or smart cards might be a ... solution and in the process actually improve security. ... i will just have to try and burn their usernames into their minds. ... This feature would be great for a domain computer that has multiple ...
    (microsoft.public.windows.server.active_directory)
  • Re: Event ID 1085 and Event ID 1202 appear after in-place upgrade of Windows 2000 to Windows XP
    ... has a fresh install of XPSP2 on it. ... the server when I get back to work tomorrow..... ... > to security settings/local policies/security options. ... > option for Microsoft network server:digitally sign communications ...
    (microsoft.public.windows.group_policy)