Google Groups no longer supports new Usenet posts or subscriptions. Historical content remains viewable.
Dismiss

Domain OS 10.4 accounts

50 views
Skip to first unread message

supervinx

unread,
Jun 23, 2012, 6:46:31 PM6/23/12
to

Hi folks !
I'm servicing another HP 400 (with this, should remain five...)
I booted happily and at the login request I wrote the pair root/password
which I found for the HP 400 machines already analyzed
(cracked with John the Ripper).
I got this message: "Account has expired or has become invalid".
If I wrote root/another password, I get the standard error message, so the
aforesaid pair should be ok.
How to break in, now ?


--
http://www.supervinx.com/Retrocomputer

supervinx

unread,
Jun 23, 2012, 7:13:08 PM6/23/12
to
Checked the HD image, the password are those.
user / -apollo- is defined, also, but I can't login ...



--
http://www.supervinx.com/Retrocomputer

Kurt Nowak

unread,
Jun 23, 2012, 11:39:35 PM6/23/12
to
Hi Vincenzo,

I never had to do this myself, but the writeup for that is in the FAQ:

http://mit.edu/kolya/www/csa-faq.html#4.24

Let us know how it goes... :)

supervinx

unread,
Jun 24, 2012, 5:10:18 AM6/24/12
to
>
> Let us know how it goes... :)
Well, this seems a complex question ...
Booted in service mode and tried

)wd /sys/registry

found two files,
rgy_local and rgy_local.bak

can't chn o dlf, not enough rights...

Looked into /etc/daemons, no llbd (rpcd), rgyd or glbd.
crf-ed them, rebooted, but no success.

Some questions:
1) may reiterate failure to login invalidate an account ?
2) /etc/passwd file, reveals root/taurus (John the Ripper), but
system responds to root/fener (found in another 400t).

root/fener ---> account expired or not valid.
root/taurus --> invalid account.

So /etc/passwd is there just for compatibility, the real password hash
is stored into rgy_local ?

3) Can I connect it to another node and try to access ? The question is:
which TCP address has ? (May find it with tcpdump) ? There will be ACL issues ?

4) Since I have a disk image of the HD, I could try a Q&D hack. Find the
directory data of /sys/registry/ and change the name from
rgy_local to _gy_local (or similar). It should boot without registry and
allow me to enter ...




--
http://www.supervinx.com/Retrocomputer

supervinx

unread,
Jun 24, 2012, 5:26:15 AM6/24/12
to

> 3) Can I connect it to another node and try to access ? The question is:
> which TCP address has ? (May find it with tcpdump) ? There will be ACL
> issues ?
>
I answer myself: netboot the "failing" machine through another Apollo node
running the same version (SR 10.4), mount the disk and rename the rgy_local...




--
http://www.supervinx.com/Retrocomputer

supervinx

unread,
Jun 24, 2012, 12:59:51 PM6/24/12
to
After some minor adjustments, netbooted the HP, mounted the local disk and
renamed rgy_local.
Rebooted and accessed the system with user/-apollo- .
Some tools were missing, like rgy_create, so did an rcp with the other machine.
The node were already catalogued, since the machines come from the same place.
All the process was a real breeze.
Recreated the registry, restarted the daemons, set up the tcp/ip parameters
and the machine is ready.
Must admit that Apollo networking was already ahead of its time.

0 new messages