How to Implement a Fake Password System for Linux Security Using pam-duress
A fake password system for Linux security creates a covert authentication backdoor that executes predefined destructive or deceptive actions when a secondary (panic) password is entered, implemented via the pam-duress PAM module and cryptographically signed scripts.
Implementing a fake password system for Linux security provides a critical defense against physical compromise or coercion by allowing you to authenticate with a decoy credential that silently triggers countermeasures. According to the How-To-Secure-A-Linux-Server repository, this technique—often called a panic or duress system—integrates into the standard PAM authentication stack without alerting attackers to its existence. This guide explains the architecture and step-by-step configuration using the pam-duress module as documented in the repository’s README (lines 1499–1585).
What Is a Fake Password (Panic) System?
A fake password system creates a parallel authentication path where entering a specific duress password instead of your real credential grants access while simultaneously triggering automated responses. These responses can range from wiping sensitive data and shutting down the system to sending silent alerts or presenting a convincing decoy environment. The system maintains plausible deniability because logs show a normal successful login, and standard users remain unaware of the secondary authentication mechanism.
Architecture of the pam-duress Implementation
As documented in the repository between lines 1499 and 1585, the implementation relies on four core components that intercept and modify authentication behavior at the PAM level.
The pam-duress PAM Module
The pam_duress.so module intercepts the authentication stack immediately after standard Unix authentication. When a user enters the duress password, the module returns success and sets an internal flag that triggers the execution of a pre-defined script. According to the source analysis, this occurs in the logic described around lines 1505–1510, where the module validates the panic credential against entries stored in /etc/security/duress.conf.
The Duress Script and Signature Verification
The duress script is any executable owned by the panic user that performs your chosen countermeasure actions—such as wiping home directories or halting the system as suggested in lines 1530–1536. Before execution, pam-duress enforces signature verification using SHA256 hashes to prevent tampering. You must sign scripts using the duress_sign utility, creating a companion .sha256 file that the module checks before invocation, as noted in lines 1571–1573.
PAM Configuration Changes
The system modifies /etc/pam.d/common-auth to insert pam_duress.so into the authentication chain after pam_unix.so. The configuration uses PAM control flags to skip subsequent modules if duress authentication succeeds, ensuring the script executes while maintaining the appearance of a normal login flow. Lines 1578–1583 detail the specific configuration that routes authentication through the duress check.
Step-by-Step Implementation Guide
Follow these steps to deploy a fake password system for Linux security on Debian-based distributions. Ensure you have established backup priorities before configuring destructive scripts.
Install Dependencies and Build pam-duress
Install build tools and PAM development libraries, then compile the module from source:
sudo apt install -y git build-essential libpam0g-dev libssl-dev
cd $HOME
git clone https://github.com/nuvious/pam-duress.git
cd pam-duress
make && sudo make install && make clean
This installs /usr/lib/security/pam_duress.so and the duress_sign utility required for script verification.
Create the Panic User and Duress Script
Select a panic user (typically root for maximum system access) and create the script directory:
read -p "Enter Panic User [root]: " PANICUSR
PANICUSR=${PANICUSR:-root}
SCRIPT_LOC="/root/.duress"
SCRIPT_FILE="${SCRIPT_LOC}/PanicScript.sh"
sudo mkdir -p "$SCRIPT_LOC"
cat > "$SCRIPT_FILE" <<'EOF'
#!/bin/bash
# Example destructive action: wipe home directories and halt
sudo rm -rf /home/*
sudo shutdown -h now
EOF
sudo chmod 500 "$SCRIPT_LOC"
sudo chown "$PANICUSR":"$PANICUSR" "$SCRIPT_FILE"
Customize the script contents based on your security requirements—options include wiping SSH keys, unmounting encrypted volumes, or triggering network alerts.
Sign the Script for Tamper Protection
Generate a cryptographic signature that pam-duress will verify before execution:
duress_sign "$SCRIPT_FILE"
This creates PanicScript.sh.sha256 in the same directory. The module refuses to execute scripts lacking valid signatures or with mismatched hashes, preventing attackers from replacing your script with malicious code.
Configure PAM to Enable Duress Authentication
Backup and modify /etc/pam.d/common-auth to include the duress module in the authentication stack:
sudo cp /etc/pam.d/common-auth /etc/pam.d/common-auth.bck
sudo tee /etc/pam.d/common-auth <<'EOF'
auth [success=2 default=ignore] pam_unix.so nullok_secure
auth [success=1 default=ignore] pam_duress.so
auth requisite pam_deny.so
auth required pam_permit.so
EOF
This configuration attempts standard Unix authentication first; if the duress password matches, pam-duress returns success and skips to the permit stage while executing your script.
Testing the Fake Password Flow
First, set your duress password by running a test authentication or editing /etc/security/duress.conf directly. Then verify both paths:
- Normal login: Enter your standard password. Authentication proceeds normally without triggering scripts.
- Panic login: Enter the duress password. The system should execute your configured script (e.g., shutdown or wipe) while logging a successful authentication.
Summary
- A fake password system for Linux security creates a covert authentication backdoor using the pam-duress module and PAM configuration changes.
- The architecture requires
pam_duress.soto intercept logins in/etc/pam.d/common-auth, a signed executable script owned by the panic user, and entries in/etc/security/duress.conf. - Signature verification via
duress_signprevents attackers from tampering with duress scripts. - According to the How-To-Secure-A-Linux-Server repository, this technique provides plausible deniability by logging successful authentication while executing destructive or deceptive countermeasures.
Frequently Asked Questions
What happens if I forget my duress password?
If you forget the duress password, you can still authenticate with your standard credentials. The duress system operates independently; forgetting it does not lock you out of the system. You can reset or remove the duress entry by editing /etc/security/duress.conf with root privileges.
Can attackers detect that a fake password system is installed?
The fake password system is designed for stealth. Standard users cannot list duress scripts or passwords without root access, and successful duress authentications appear identical to normal logins in system logs. However, sophisticated forensic analysis of /etc/pam.d/common-auth or the presence of /usr/lib/security/pam_duress.so could reveal the module.
Is the duress script executed with root privileges?
Yes, when configured for the root user or users with sudo capabilities, the duress script executes with the full privileges of the account used for authentication. This allows comprehensive system actions like wiping disks or shutting down services, but requires careful script validation to avoid accidental data loss during testing.
Which Linux distributions support pam-duress?
The pam-duress module compiles on any Linux distribution with PAM support and standard development libraries. The How-To-Secure-A-Linux-Server guide specifically targets Debian-based systems (Ubuntu, Debian) using apt for dependencies, but the source code at https://github.com/nuvious/pam-duress can be built on RHEL, CentOS, Arch, and other distributions with make and libpam development headers.
Have a question about this repo?
These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:
curl -s "https://instagit.com/install.md" Maintain an open-source project? Get it listed too →