dear forum members,
i came across of very serious security problem. few minutes ago i have tried to install Skype (skype-1.4.0.118-suse.i586.RPM) downloaded from skype website.As usual i tried to install it with clicking on it - then as expected YAST password manager popped up and ask me for password - i typed it in and install started. But!!! it didn't go further then "Reading Installed Packages" and then yast install window would dissappear from screen.
Next is what astonished me. I tried to install it again thinking that probably something went wrong first time - same thing. Then i have tried again and few times again, after getting same result during the last attempt being angry i have just ran my hand on the keyboard when asked for a password and pushed "enter" key. To my suprise it didn't tell me that i have typed in wrong password but just started to " install" package (unsuccessfully of course).
Then i have tried to start yast - pop up password window - i typed wrong password - it got accepted!!!!!! to try if it didn't just opened a YAST manager without functioning i tried unistall Firefox and it did unistall it.
So .... installing skype didn't work, but insted my system is accepting any password!!!!!
what i have found later is after more then five minutes security kicks back in. what i mean is it doesn't accept wrong passwords any more. but with every new attempt to install Skype - security is down for a 5 or so minutes.
please tell me if you need some log files to look at this more in details (and please tell me where i find those logs)
senserely
Nikolai
|