Index: [Article Count Order] [Thread]

Date:  Tue, 15 May 2007 16:02:33 +1000
From:  Greg Kuhnert <greg.kuhnert (at mark) theanchoragesylvania.com>
Subject:  [coba-e:09845] PAM / dovecot
To:  coba-e (at mark) bluequartz.org
Message-Id:  <46494CF9.50105 (at mark) theanchoragesylvania.com>
X-Mail-Count: 09845

Hi all.

I was looking around for something earlier today that was totally 
un-related to BQ, and I came across a brute force password tool that I 
had seen many years ago by the name of brutus. I thought Hey, that could 
help track down the Dovecot/PAM problems on BQ.

I have not had much of a play yet, but I did create an attack against my 
own mail server, and I was able to trash it in a matter of moments. All 
PAM authentication was failing, and dbrecover was needed.

I will have another play in the near future, but firstly, does anyone 
know much about the PAM module we use? What debugging can we enable?

Regards,
Greg.

-- 
This message has been scanned for viruses and
dangerous content by MailScanner, and is
believed to be clean.