Subject: Re: Insecure Password?
To: Ken Hornstein <kenh@cmf.nrl.navy.mil>
From: Feico Dillema <dillema@acm.org>
List: netbsd-help
Date: 07/09/1998 15:57:21
Your message dated: Thu, 09 Jul 1998 09:45:36 -0400
>I _have_ seen, once in my life, two passwords which hashed to the same
>thing (I only discovered it because we were running Crack).  It is
>possible that you've run into the same thing.
>
>Do _other_ random passwords let you log into this account?  Or is it
>only these two?  And if you don't mind, you could always tell us
>the two passwords and corresponding hashed output (after changing it
>on your side, of course :-) ).

This evening I'll do some more testing and see how reproducible this is.
I saw it on my alpha box, I'll also try it on an Intel box and try some 
other variations of the passwd to. There was another strange thing with this 
password, in that it `didn't work' from a Win95 machine to the SAMBA server.
Changing the password `solved' it. Well, I've seen stranger things from 
Windows-boxes <sigh>. 

I hope to give a nice report about it this evening or tomorrow....

Feico.