# How to Implement a Fake Password System for Linux Security Using pam-duress

> Implement a fake password system for Linux security with pam-duress. Create a covert backdoor for destructive or deceptive actions using a panic password and signed scripts.

- Repository: [IMTheNachoMan/How-To-Secure-A-Linux-Server](https://github.com/imthenachoman/How-To-Secure-A-Linux-Server)
- Tags: how-to-guide
- Published: 2026-05-14

---

**A fake password system for Linux security creates a covert authentication backdoor that executes predefined destructive or deceptive actions when a secondary (panic) password is entered, implemented via the pam-duress PAM module and cryptographically signed scripts.**

Implementing a fake password system for Linux security provides a critical defense against physical compromise or coercion by allowing you to authenticate with a decoy credential that silently triggers countermeasures. According to the How-To-Secure-A-Linux-Server repository, this technique—often called a panic or duress system—integrates into the standard PAM authentication stack without alerting attackers to its existence. This guide explains the architecture and step-by-step configuration using the pam-duress module as documented in the repository’s README (lines 1499–1585).

## What Is a Fake Password (Panic) System?

A fake password system creates a parallel authentication path where entering a specific **duress password** instead of your real credential grants access while simultaneously triggering automated responses. These responses can range from wiping sensitive data and shutting down the system to sending silent alerts or presenting a convincing decoy environment. The system maintains **plausible deniability** because logs show a normal successful login, and standard users remain unaware of the secondary authentication mechanism.

## Architecture of the pam-duress Implementation

As documented in the repository between lines 1499 and 1585, the implementation relies on four core components that intercept and modify authentication behavior at the PAM level.

### The pam-duress PAM Module

The `pam_duress.so` module intercepts the authentication stack immediately after standard Unix authentication. When a user enters the duress password, the module returns success and sets an internal flag that triggers the execution of a pre-defined script. According to the source analysis, this occurs in the logic described around lines 1505–1510, where the module validates the panic credential against entries stored in [`/etc/security/duress.conf`](https://github.com/imthenachoman/How-To-Secure-A-Linux-Server/blob/main//etc/security/duress.conf).

### The Duress Script and Signature Verification

The **duress script** is any executable owned by the panic user that performs your chosen countermeasure actions—such as wiping home directories or halting the system as suggested in lines 1530–1536. Before execution, pam-duress enforces **signature verification** using SHA256 hashes to prevent tampering. You must sign scripts using the `duress_sign` utility, creating a companion `.sha256` file that the module checks before invocation, as noted in lines 1571–1573.

### PAM Configuration Changes

The system modifies `/etc/pam.d/common-auth` to insert `pam_duress.so` into the authentication chain after `pam_unix.so`. The configuration uses PAM control flags to skip subsequent modules if duress authentication succeeds, ensuring the script executes while maintaining the appearance of a normal login flow. Lines 1578–1583 detail the specific configuration that routes authentication through the duress check.

## Step-by-Step Implementation Guide

Follow these steps to deploy a fake password system for Linux security on Debian-based distributions. Ensure you have established backup priorities before configuring destructive scripts.

### Install Dependencies and Build pam-duress

Install build tools and PAM development libraries, then compile the module from source:

```bash
sudo apt install -y git build-essential libpam0g-dev libssl-dev
cd $HOME
git clone https://github.com/nuvious/pam-duress.git
cd pam-duress
make && sudo make install && make clean

```

This installs `/usr/lib/security/pam_duress.so` and the `duress_sign` utility required for script verification.

### Create the Panic User and Duress Script

Select a panic user (typically root for maximum system access) and create the script directory:

```bash
read -p "Enter Panic User [root]: " PANICUSR
PANICUSR=${PANICUSR:-root}
SCRIPT_LOC="/root/.duress"
SCRIPT_FILE="${SCRIPT_LOC}/PanicScript.sh"

sudo mkdir -p "$SCRIPT_LOC"
cat > "$SCRIPT_FILE" <<'EOF'
#!/bin/bash

# Example destructive action: wipe home directories and halt

sudo rm -rf /home/*
sudo shutdown -h now
EOF

sudo chmod 500 "$SCRIPT_LOC"
sudo chown "$PANICUSR":"$PANICUSR" "$SCRIPT_FILE"

```

Customize the script contents based on your security requirements—options include wiping SSH keys, unmounting encrypted volumes, or triggering network alerts.

### Sign the Script for Tamper Protection

Generate a cryptographic signature that pam-duress will verify before execution:

```bash
duress_sign "$SCRIPT_FILE"

```

This creates `PanicScript.sh.sha256` in the same directory. The module refuses to execute scripts lacking valid signatures or with mismatched hashes, preventing attackers from replacing your script with malicious code.

### Configure PAM to Enable Duress Authentication

Backup and modify `/etc/pam.d/common-auth` to include the duress module in the authentication stack:

```bash
sudo cp /etc/pam.d/common-auth /etc/pam.d/common-auth.bck
sudo tee /etc/pam.d/common-auth <<'EOF'
auth    [success=2 default=ignore]   pam_unix.so nullok_secure
auth    [success=1 default=ignore]   pam_duress.so
auth    requisite                     pam_deny.so
auth    required                      pam_permit.so
EOF

```

This configuration attempts standard Unix authentication first; if the duress password matches, pam-duress returns success and skips to the permit stage while executing your script.

### Testing the Fake Password Flow

First, set your duress password by running a test authentication or editing [`/etc/security/duress.conf`](https://github.com/imthenachoman/How-To-Secure-A-Linux-Server/blob/main//etc/security/duress.conf) directly. Then verify both paths:

1. **Normal login**: Enter your standard password. Authentication proceeds normally without triggering scripts.
2. **Panic login**: Enter the duress password. The system should execute your configured script (e.g., shutdown or wipe) while logging a successful authentication.

## Summary

- A **fake password system for Linux security** creates a covert authentication backdoor using the pam-duress module and PAM configuration changes.
- The architecture requires `pam_duress.so` to intercept logins in `/etc/pam.d/common-auth`, a **signed executable script** owned by the panic user, and entries in [`/etc/security/duress.conf`](https://github.com/imthenachoman/How-To-Secure-A-Linux-Server/blob/main//etc/security/duress.conf).
- **Signature verification** via `duress_sign` prevents attackers from tampering with duress scripts.
- According to the How-To-Secure-A-Linux-Server repository, this technique provides plausible deniability by logging successful authentication while executing destructive or deceptive countermeasures.

## Frequently Asked Questions

### What happens if I forget my duress password?

If you forget the duress password, you can still authenticate with your standard credentials. The duress system operates independently; forgetting it does not lock you out of the system. You can reset or remove the duress entry by editing [`/etc/security/duress.conf`](https://github.com/imthenachoman/How-To-Secure-A-Linux-Server/blob/main//etc/security/duress.conf) with root privileges.

### Can attackers detect that a fake password system is installed?

The fake password system is designed for **stealth**. Standard users cannot list duress scripts or passwords without root access, and successful duress authentications appear identical to normal logins in system logs. However, sophisticated forensic analysis of `/etc/pam.d/common-auth` or the presence of `/usr/lib/security/pam_duress.so` could reveal the module.

### Is the duress script executed with root privileges?

Yes, when configured for the root user or users with sudo capabilities, the duress script executes with the full privileges of the account used for authentication. This allows comprehensive system actions like wiping disks or shutting down services, but requires careful script validation to avoid accidental data loss during testing.

### Which Linux distributions support pam-duress?

The pam-duress module compiles on any Linux distribution with PAM support and standard development libraries. The How-To-Secure-A-Linux-Server guide specifically targets Debian-based systems (Ubuntu, Debian) using `apt` for dependencies, but the source code at https://github.com/nuvious/pam-duress can be built on RHEL, CentOS, Arch, and other distributions with `make` and `libpam` development headers.