<aside> <img src="/icons/battery-charging_green.svg" alt="/icons/battery-charging_green.svg" width="40px" />

Linux Authentication Process

</aside>

Linux-based distributions support various authentication mechanisms. One of the most commonly used is Pluggable Authentication Modules (PAM). The modules responsible for this functionality, such as pam_unix.so or pam_unix2.so, are typically located in /usr/lib/x86_64-linux-gnu/security/ on Debian-based systems. These modules manage user information, authentication, sessions, and password changes. For example, when a user changes their password using the passwd command, PAM is invoked, which takes the appropriate precautions to handle and store the information accordingly.

The pam_unix.so module uses standardized API calls from system libraries to update account information. The primary files it reads from and writes to are /etc/passwd and /etc/shadow. PAM also includes many other service modules, such as those for LDAP, mount operations, and Kerberos authentication.


Passwd file 🎯

The /etc/passwd file contains information about every user on the system and is readable by all users and services. Each entry in the file corresponds to a single user and consists of seven fields, which store user-related data in a structured format. These fields are separated by colons (:). As such, a typical entry may look something like this:

htb-student:x:1000:1000:,,,:/home/htb-student:/bin/bash

Field Value
Username htb-student
Password x
User ID 1000
Group ID 1000
GECOS ,,,
Home directory /home/htb-student
Default shell /bin/bash

The most relevant field for our purposes is the Password field, as it can contain different types of entries. In rare cases (generally on very old systems) this field may hold the actual password hash. On modern systems, however, password hashes are stored in the /etc/shadow file, which we'll examine later. Despite this, the /etc/passwd file is world-readable, giving attackers the ability to crack the passwords if hashes are stored here.

<aside> <img src="/icons/warning_red.svg" alt="/icons/warning_red.svg" width="40px" />

Usually, we will find the value x in this field, indicating that the passwords are stored in a hashed form within the /etc/shadow file. However, it can also be that the /etc/passwd file is writeable by mistake. This would allow us to remove the password field for the root user entirely.

0xWALY@htb[/htb]$ head -n 1 /etc/passwd

root::0:0:root:/root:/bin/bash

This results in no password prompt being displayed when attempting to log in as root.

Linux Authentication Process

0xWALY@htb[/htb]$ su

root@htb[/htb]#

</aside>

Shadow file🎯

Since reading password hash values can put the entire system at risk, the /etc/shadow file was introduced. It has a similar format to /etc/passwd but is solely responsible for password storage and management. It contains all password information for created users. For example, if there is no entry in the /etc/shadow file for a user listed in /etc/passwd, that user is considered invalid. The /etc/shadow file is also only readable by users with administrative privileges. The format of this file is divided into the following nine fields:

htb-student:$y$j9T$3QSBB6CbHEu...SNIP...f8Ms:18955:0:99999:7:::

Field Value
Username htb-student
Password $y$j9T$3QSBB6CbHEu...SNIP...f8Ms
Last change 18955
Min age 0
Max age 99999
Warning period 7
Inactivity period -
Expiration date -
Reserved field -

The Password field also follows a particular format, from which we can extract additional information:

As we can see here, the hashed passwords are divided into three parts. The ID value specifies which cryptographic hash algorithm was used, typically one of the following:

ID Cryptographic Hash Algorithm
1 MD5
2a Blowfish
5 SHA-256
6 SHA-512
sha1 SHA1crypt
y Yescrypt
gy Gost-yescrypt
7 Scrypt

Opasswd