View Issue Details
ID | Project | Category | View Status | Date Submitted | Last Update |
---|---|---|---|---|---|
0008185 | Gov (US) | General | public | 2024-11-10 15:29 | 2024-11-10 16:05 |
Reporter | Ryan Fitzgerald | Assigned To | |||
Priority | urgent | Severity | block | Reproducibility | unable to reproduce |
Status | new | Resolution | open | ||
Summary | 0008185: Credentials are changed after install when connected to network | ||||
Description | I have tried with both RHEL 9 (which requires an internet connection for subscription management) and Rocky 9.4 If I am connected to the internet when using a DISA STIG for GUI and set my new password after initial login, I catch ethernet frames sending packets that change the credentials to something random, preventing me sudo access once I'm logged in. | ||||
Tags | No tags attached. | ||||
It makes this and RHEL and Rocky impossible to use for any government contract work whatsoever. And Ubuntu is not preferred. | |
I should have said "as soon as connected to internet and logging in with the GUI" the password is changed. I'm done trying, eventually I just kept the internet attached to catch the frames. | |
Last note. It's actually a win for Rocky and RHEL. Attackers have to lock the user out to prevent them from switching to a different, more vulnerable OS. I'd check for network stack activity within password management. |
|
They're using 0.0.0.0/0 for the ip and ff:ff:ff:ff:ff:ff for the mac in these frames. I mean that's one way. But it can be changed to anything. | |
Apple does these type of checks through GUI checks. They make sure in their pam modules that there is an active GUI session initiating the pam auth request. But the server install has the same issue. | |
Date Modified | Username | Field | Change |
---|---|---|---|
2024-11-10 15:29 | Ryan Fitzgerald | New Issue | |
2024-11-10 15:31 | Ryan Fitzgerald | Note Added: 0008713 | |
2024-11-10 15:34 | Ryan Fitzgerald | Note Added: 0008714 | |
2024-11-10 15:44 | Ryan Fitzgerald | Note Added: 0008715 | |
2024-11-10 15:48 | Ryan Fitzgerald | Note Added: 0008716 | |
2024-11-10 16:05 | Ryan Fitzgerald | Note Added: 0008717 |