Thursday, March 15, 2007

Hi

BASICS OF UNIX (I’ll explain mainly Linux cause it’s the choice of beginners)

Well unix as you all know is an operating system which has a lot of variants (I wont go into much details about the different variant of unix and the workings and needs of them).

Further it is the operating system the source code of which is freely available for download on the internet cause the author grandly welcomes you to edit it and make the *nix community improve unix.. so if you are a unix guru.. or have a good deal of idea about kernel programming and things like that… you can put ur name in the *nix community by editing and modifying unix..

Anyway lets come to the very basics of the workings of Linux totally intended to those who are really really new to Linux..

Well by definition , Linux is a multi-user, multi-tasking Operating system which maintains user accounts of different permissions and uses username-password authentication type for authenticating a valid user into his account..

By permission I mean the authority of a particular user to read, write or execute particular files or directories.. since it is a multi-user operating system the system administrator can easily configure it accordingly to restrict the permission of certain class of users.. generally the ‘root’ is the account of maximum permission. Speaking briefly this account is not even used by system administrators on regular basis.. they mainly use it for system configurations.. so if you somehow made yourself into the root account then ur the boss.. you got the system baby.. you can do whatever you wanna do with it..

Different accounts have different home directories, shell may be same or different.. , different user ID (UID) but one thing may be common in between two users and that is the GID (group ID).. System administrators often divide the users of a system into groups and then create respective permission for each group thus making his task much easier and quicker..

This is evident from the password file of Linux.. by default Linux stores its password file which is store in /etc/passwd

Use cat command to view the passwd file..

$cat /etc/passwd

abhisek:wrhwfhsfhslfhlsffhsfhsf:1:3:Abhisek Datta (admin):/root:/bin/bash

beginner:sjfhsgfjgfsjgfjgsff:1:2::5:Account for Beginner:/root/beginner:/bin/bash

[ a typical example of a line taken from the passwd file of earlier versions of linux]

$cat /etc/passwd

abhisek:x:0:1:Abhisek Datta:/root:/bin/bash

beginner:x:1:2::5:Account for Beginner:/root/beginner:/bin/bash

[a typical example of a line taken from the passwd file of the latest versions of linux and also other variants of unix]

thus the basic format of Linux passwd file is :

username:encrypted password:userID:GroupID:Account Description:Homedirectory:Shell

Evidently most of you people have figure out the difference in the password file of earlier version of Linux to the versions of present… the encrypted password is replaced by a ‘x’

Let me tell you something.. previously.. the Hackers of the past used to find out this kinds information using their efforts and skills, by trial and error method, using their incomparable intelligence.. but now we people.. what we do… do nothing but to read others manuals and study it, research on it and then write a manual on it according to our knowledge and things we have found out..but the very basis of our knowledge comes from the accomplishments of the hackers of the past—The Legends.. this is a fact which we cant deny..

Since now it is quite easy to learn hacking (by definition hacking means..finding out loopholes in systems and bugs in programs that can be exploited..and the term hacker means a person of wide and advanced knowledge of programming.. plz note.. this definition is by far from over) (I have realized the real meaning of the term hacker.. so I don’t consider myself to be a hacker yet) nowadays cause there are so many books and manuals around us to learn.. so I think the security must be improved to a large extend so that we can do something by our own.. we can make our self proud in our eyes…

Lets come to the point.. sorry for moving out from the topic but I think its necessary for you people to know the real meaning of hacking..

Any way in the recent versions of Linux (or better to say in most *nix variants..since I am mainly concerned with Linux. i’ll tak about Linux only) the encrypted password is replaced by a ‘x’ or a ‘*’…

This method is called “Password Shadowing”..

According to this method the encrypted password is not stored in the /etc/passwd file instead it is stored generally (not always and system administrator can easily change it) in /etc/shadow file.. the place of encrypted password in the passwd file is replaced by a * or a x .

Well for cracking the Linux password file you need to get this encrypted password and use any password cracker like ‘John the Ripper’ or ‘Cracker Jack’ etc to crack it by a method called dictionary attack (since the both the tools uses dictionary containing a number of possible password to crack the encryption) or by using brute force method.… this is just a brief over view.. I’ll explain it more clearly later on..

Well I guess you are now familiar with the Linux password file and the format of the password file including the very recent password shadowing security feature of Linux.. I’ll come to the topic of cracking the Unix password file later on which is the main point of this manual.. but I guess I should reproduce a small hack of Linux which I came across recently..

0 Comments:

Post a Comment

Subscribe to Post Comments [Atom]

<< Home