home *** CD-ROM | disk | FTP | other *** search
- Newsgroups: comp.security.misc
- Path: sparky!uunet!cs.utexas.edu!zaphod.mps.ohio-state.edu!moe.ksu.ksu.edu!ux1.cso.uiuc.edu!news.iastate.edu!john
- From: john@iastate.edu (John Hascall)
- Subject: Re: unhappy about overloading finger
- Message-ID: <1992Jul25.023851.482@news.iastate.edu>
- Sender: news@news.iastate.edu (USENET News System)
- Organization: Iowa State University, Ames, IA
- References: <1992Jul24.100650.9235@nntpd.lkg.dec.com> <dag.712016415@ossi.com>
- Date: Sat, 25 Jul 1992 02:38:51 GMT
- Lines: 20
-
- dag@ossi.com (Darren Alex Griffiths) writes:
- }coar@Nephi.Enet.DEC.Com (Rodent of Unusual Size) writes:
- }> So what's supposed to happen? I'm running a system with standard ULTRIX
- }> (other than modified FTP), and all this does is a full finger of the
- }> passwd file of the remote system. Is that the screwup? ...
- }It's definately a major screwup. This allows the pond scum who try and
- }break into systems to get a list off all users and then attempt to crack the
- ...
- }Instead it should complain about the bogus user not existing.
-
- I like our fix better, try: finger @@iastate.edu
- (a bunch of gotta-try-it students doing this on a system with 7000 passwd
- entries convinced us to fix this in a hurry before system meltdown).
-
- John
- --
- John Hascall ``Live with it pink-boy!''
- Project Vincent
- Iowa State University Computation Center john@iastate.edu
- Ames, IA 50011 515/294-9551 [fax -1717]
-