Gentoo Archives: gentoo-security

From: Sebastian Siewior <gentoo-security@×××××××××××××.cc>
To: gentoo-security@l.g.o
Subject: Re: [gentoo-security] PAM/passwd? and hash tables
Date: Tue, 15 Nov 2005 13:43:05
Message-Id: 20051115133532.GD7534@Chamillionaire.breakpoint.cc
In Reply to: [gentoo-security] PAM/passwd? and hash tables by Stuart Howard
1 * Stuart Howard | 2005-11-15 13:03:48 [+0000]:
2
3 >Hi
4 Hi,
5
6 >My specific question is this - What method/cryptography is used to
7 >create the passwd hash under PAM ie. is it vunerable to rainbow type
8 >hash tables.
9 MD5 or SHA1 with "salt" and therefore it is _not_.
10
11 >PAM that generates the hash of my chosen password?
12 Almost. It is done by one of pam's module. Look in /etc/pam.d
13
14 >Does the "NBS DES algorithm" come under the "salt" method? and is it
15 The salt method is not algorithm specific. Emerge john and let it run on
16 your local passwords and you will know what it is :)
17 As far I remember the DES version was with salt, too (I have no clue
18 what NBS stands for).
19
20 >regards
21 >
22 >stuart
23 --
24 regards
25 Sebastian Siewior
26 --
27 gentoo-security@g.o mailing list