View Issue Details

IDProjectCategoryView StatusLast Update
0008185Gov (US)Generalpublic2024-11-10 16:05
ReporterRyan Fitzgerald Assigned To 
PriorityurgentSeverityblockReproducibilityunable to reproduce
Status newResolutionopen 
Summary0008185: Credentials are changed after install when connected to network
DescriptionI have tried with both RHEL 9 (which requires an internet connection for subscription management) and Rocky 9.4

If I am connected to the internet when using a DISA STIG for GUI and set my new password after initial login, I catch ethernet frames sending packets that change the credentials to something random, preventing me sudo access once I'm logged in.
TagsNo tags attached.

Activities

Ryan Fitzgerald

Ryan Fitzgerald

2024-11-10 15:31

reporter   ~0008713

It makes this and RHEL and Rocky impossible to use for any government contract work whatsoever. And Ubuntu is not preferred.
Ryan Fitzgerald

Ryan Fitzgerald

2024-11-10 15:34

reporter   ~0008714

I should have said "as soon as connected to internet and logging in with the GUI" the password is changed. I'm done trying, eventually I just kept the internet attached to catch the frames.
Ryan Fitzgerald

Ryan Fitzgerald

2024-11-10 15:44

reporter   ~0008715

Last note.

It's actually a win for Rocky and RHEL. Attackers have to lock the user out to prevent them from switching to a different, more vulnerable OS.

I'd check for network stack activity within password management.
Ryan Fitzgerald

Ryan Fitzgerald

2024-11-10 15:48

reporter   ~0008716

They're using 0.0.0.0/0 for the ip and ff:ff:ff:ff:ff:ff for the mac in these frames. I mean that's one way. But it can be changed to anything.
Ryan Fitzgerald

Ryan Fitzgerald

2024-11-10 16:05

reporter   ~0008717

Apple does these type of checks through GUI checks. They make sure in their pam modules that there is an active GUI session initiating the pam auth request. But the server install has the same issue.

Issue History

Date Modified Username Field Change
2024-11-10 15:29 Ryan Fitzgerald New Issue
2024-11-10 15:31 Ryan Fitzgerald Note Added: 0008713
2024-11-10 15:34 Ryan Fitzgerald Note Added: 0008714
2024-11-10 15:44 Ryan Fitzgerald Note Added: 0008715
2024-11-10 15:48 Ryan Fitzgerald Note Added: 0008716
2024-11-10 16:05 Ryan Fitzgerald Note Added: 0008717