2.4 Bug(feature?): Case-insensitive login & sessions

2.4 Bug(feature?): Case-insensitive login & sessions

Post by Ken Herse » Fri, 23 Jun 1995 04:00:00



Here's either a weird bug, or an undocumented feature:

At the login prompt, press the caps lock and enter your username.
(It will be in all caps). Remove the caps lock, and enter your
password.

It WILL log you in with the caps username (sol 2.3 won't!) and then
all text on the console will be in caps. You can enter commands in
caps or not (but it will appear in caps) and they will work fine.
There are some backslashes (\) before some letters? but besides that
it works fine, in this weird case insensitive mode.

Why? Who cares? Well, it seemed weird that it allowed my login with
all caps, so maybe there's some security issue.

Maybe not... Just a weird tidbit I found in 2.4 to pass along.

Best to all,
--

Head, Antenna and Tracking Section      http://jazzman.gsfc.nasa.gov/737.1.html
NASA/GSFC Code 737.1                    Voice:  (301)-286-8665
Greenbelt, MD 20771                     Fax:    (301)-286-1750

 
 
 

2.4 Bug(feature?): Case-insensitive login & sessions

Post by Casper H.S. Dik - Network Security Engine » Sat, 24 Jun 1995 04:00:00



>At the login prompt, press the caps lock and enter your username.
>(It will be in all caps). Remove the caps lock, and enter your
>password.

Actually, this should be "at the ttymon supplied login prompt".
If you first time your username nocaps, login will take over and
it will *not* accept a all-caps login name.

Quote:>It WILL log you in with the caps username (sol 2.3 won't!) and then
>all text on the console will be in caps. You can enter commands in
>caps or not (but it will appear in caps) and they will work fine.
>There are some backslashes (\) before some letters? but besides that
>it works fine, in this weird case insensitive mode.

It isn't case-insensitive mode.  It's "this terminal has only caps mode".
The letters with backslashes in front of them are caps.

Quote:>Why? Who cares? Well, it seemed weird that it allowed my login with
>all caps, so maybe there's some security issue.

It doesn't, really.  What happens is that all the CAPS input, unless
preceded with a \, will be converted to lowercase before being passed
to the program.  All output is converted to uppercase (uppercase output
is converted to \X, so "Login" becomes "\LOGIN".)

The only security issue I see is that you don't have capitals in your
password :-)

Casper

--
Expressed in this posting are my opinions.  They are in no way related
to opinions held by my employer, Sun Microsystems.

 
 
 

2.4 Bug(feature?): Case-insensitive login & sessions

Post by Ken Herse » Sat, 24 Jun 1995 04:00:00


Thanks to all for this history lesson about old terminals
with no lower-case. That clears it up!
Regards to all,
--

Head, Antenna and Tracking Section      http://jazzman.gsfc.nasa.gov/737.1.html
NASA/GSFC Code 737.1                    Voice:  (301)-286-8665
Greenbelt, MD 20771                     Fax:    (301)-286-1750
 
 
 

2.4 Bug(feature?): Case-insensitive login & sessions

Post by DI Elser Gerha » Sat, 24 Jun 1995 04:00:00



>Here's either a weird bug, or an undocumented feature:

>At the login prompt, press the caps lock and enter your username.
>(It will be in all caps). Remove the caps lock, and enter your
>password.

>It WILL log you in with the caps username (sol 2.3 won't!) and then
>all text on the console will be in caps. You can enter commands in
>caps or not (but it will appear in caps) and they will work fine.
>There are some backslashes (\) before some letters? but besides that
>it works fine, in this weird case insensitive mode.

>Why? Who cares? Well, it seemed weird that it allowed my login with
>all caps, so maybe there's some security issue.

>Maybe not... Just a weird tidbit I found in 2.4 to pass along.

>Best to all,
>--


This is not Solaris specific but it is an old unix behaviour from the past
where not all terminals got uppercase and lowercase characters.

So if you enter only uppercase letters at login unix switches to a mode
where all lowercase characters are written as uppercase and uppercase
characters are marked with a \ before them.

Try it on an old terminal ;-D
--
        o                    Dipl.Ing. Gerhard ELSER
      o                      Head of Development Department
    O
 __O_____F_O_C_U_S______     SEIERSBERG, Austria
   O     EDV GesmbH

      o                      Tel: +43 316 28 16 16 90
        o                    Fax: +43 316 28 16 16 983 or 981

 
 
 

1. case-insensitive file system with Apache being case-sensitive.

Hi,
    does anybody know if I can change Apache from being case-sensitive?
The problem is that I've made a web site with a protected area, when I enter
the URL www.mysite.com/protected , I need to enter a password, but if I
enter www.mysite.com/Protected or www.mysite.com/proTected I enter the web
site without bieng prompt to enter a password.

    The only way I figured out is to configure Apache for all the
possibility, like: protected, Protected, PRotected, etc....

Any help will be appreciated.

Thanks.

--
Maxime Paquette

Scripto Centris Inc.
1030 Beaubien Est #103
Montreal, Quebec
H2S 1T4
(514) 277-6148
--

2. FS: Multia 16MB True Parity Gold RAM

3. Case-insensitive matching in bash - Again

4. Apache 1.1.1 and 2.0.15-2.0.18

5. how to make regexp case-insensitive using sed

6. Please help

7. Case-insensitive filename completion in zsh?

8. Can't switch VC's in RAW keyboard mode (Dosemu)

9. Apache: Case-Insensitive <Location>?

10. How to perform a case-insensitive search in VI?

11. Can sed be case-insensitive?

12. regexp case-insensitive

13. Case-insensitive matching of substring in bash ?