IT Forensics · Linux

Forensic analysis of /etc/passwd and /etc/shadow – Examining central account databases in detail

The /etc/passwd file contains basic account information such as username, UID, GID, home directory and default shell, whilst /etc/shadow stores the actual hashed password information, as well as expiry and change dates, separately and with stronger protection.

Enquire without obligation

For forensic analysis, it is particularly important to determine whether and when entries have been altered retrospectively, for example by adding an account with UID 0 or by changing a password hash without any apparent valid reason.

Why LanCologne?

Since its foundation, LanCologne has specialised in professional IT forensics. Our staff have decades of experience in the field of information technology and assist companies, solicitors, private individuals and, on a regular basis, the courts in the technical investigation of complex digital matters.

The examination is, as a matter of principle, carried out exclusively on a forensic copy, a forensic image or a data source captured in a technically equivalent manner that preserves the integrity of the evidence. The original evidence remains unchanged and is stored in a manner that preserves its integrity.

Our services

We systematically analyse /etc/passwd and /etc/shadow for unusual accounts, particularly those with UID 0 or unexpected shell assignments, and evaluate any available timestamp information relating to the change history.

Typical areas of application

Identification of additional accounts with administrator rights (UID 0)
Investigation into retrospective changes to password hashes
Analysis of unusual shell or home directory assignments
Reconstruction of the change history for account data
Incident Response on Linux Systems
Judicial and non-judicial expert reports

This is how an analysis of /etc/passwd and /etc/shadow is carried out

Once backed up, both files are analysed systematically and checked for accounts with UID 0, unexpected shell assignments or atypical home directories. Available timestamps and file system metadata are used to narrow down the times at which individual entries were modified.

Why is this analysis relevant from a forensic perspective?

An additional account with UID 0 has the same privileges as the standard root user and therefore represents one of the most critical potential persistence mechanisms in the event of a system compromise.

As these files contain key security information, they are always analysed with particular care and cross-referenced against other log sources.

Frequently Asked Questions

What does a second account with UID 0 mean?+
It has the same administrator rights as the standard root account, regardless of the chosen username, and must therefore be viewed with particular caution.
Can password hashes be decrypted?+
With modern hashing algorithms, decryption is not feasibly possible given the current state of the art. Forensic analysis focuses on the timing and patterns of changes.
How can subsequent tampering be detected?+
This is achieved, amongst other things, by comparing file system timestamps, backup statuses and other log sources such as Auditd.

LanCologne – Linux Forensics Cologne

Do you require a professional forensic investigation into „forensic analysis of /etc/passwd and /etc/shadow"? LanCologne can assist you with the legally admissible preservation of digital evidence and the transparent analysis of relevant Linux artefacts.

Get in touch now