Blue Bubble
Sharper than a thorn
Ok, here's another story of password retrieval. It required an account on the target machine, so you could use it for privilege escalation. The authentication routine would reject the password at the first wrong character it reached. Of course this didn't happen at the keyboard level, but at the internal level of the authentication routine scanning the string passed to it. However, if you arranged for the password to straddle a page boundary, and arranged for the second page to be paged out, you could, through timing, guess how far along the password the checker had got. Of course there's some randomness here, and arranging for a just written-to page to be probably paged out is tricky. But it did work, and it did cause a software update to make the scanner scan the whole password regardless. Hm, not sure why you'd simply do this where the next page wasn't available and catch a segmentation fault. I think it was VMS and I'm not very familiar with its internals.
No, it could not have been VMS. That's never been the way VMS checks passwords.
And, yes, I am very familiar with VMS internals - that's my job, and has been for the last 27 years.
Last edited: