home *** CD-ROM | disk | FTP | other *** search
- Newsgroups: comp.security.misc
- Path: sparky!uunet!ulowell!cs.ulowell.edu!oneill
- From: oneill@cs.ulowell.edu (Brian 'Doc' O'Neill)
- Subject: Re: Pleasure.com mystery solved.
- Message-ID: <1992Jul27.203230.12185@ulowell.ulowell.edu>
- Sender: usenet@ulowell.ulowell.edu (News manager - ulowell)
- Organization: University of Massachusetts at Lowell Computer Science
- References: <1992Jul27.135126.1626@drycas.club.cc.cmu.edu>
- Date: Mon, 27 Jul 1992 20:32:30 GMT
- Lines: 50
-
- In article <1992Jul27.135126.1626@drycas.club.cc.cmu.edu> greenie@drycas.club.cc.cmu.edu writes:
- >To settle the stories and quench the rumor mongers, "pleasure.com" was
- >a test site that we had set up as a demonstration to determine the "market
- >demand" for an adult service on the commercial internet. It was only set
- >up for a short period of time, and there were a number of users connecting
- >to it. But since it was a test and not expected to remain online forever,
- >we did not bother registering the domain name - and we were under no obligation
- >to do so because it was through the commercial Internet and therefor not
- >under the auspices of the NIC and the NSF.
- >
-
- I'm not so sure about not being under the auspices of the NIC - the NSF, no,
- but someone controls domain and IP allocations for the Commercial Internet
- as well. I accept your explanations for what you did, I just feel it was
- done poorly. Someone should have been made aware.
-
- >We were NOT "storing up passwords" as some users have suggested. Rather,
- >since *WE* are just as concerned about security as other people apparently
- >are, we set up our system so that it would FTP TO the users home site and
- >place files there, rather than allowing them to connect freely to our
- >machines using FTP. Users who are not happy with doing this are not being
- >forced to transfer files this way. They're not being forced to transfer
- >files at all.
- >
-
- I didn't suggest that you were storing passwords, I was just concerned about
- the mechanism to do so, which hasn't been explained. Is it the users
- themselves which do the FTP? From what I saw, it seemed to be an automated
- process, which would have required the storing of the password to connect to
- the user's remote account. I could be wrong - I hope I am - but it sure
- looked automated, and unsuccessful at that.
-
- >Because of the original individuals negative comments and paranoia with the
- >connections (rather than approaching us first), we will probably choose
- >another REGISTERED domain name in the future.
- >
-
- Security is inherently paranoid...
-
- I don't think my comments were necessarily negative, just concerned. When
- one has a system being broken in to, does one go to the cracker and ask what
- they are doing? I went to the best resource available, UseNet, to find out
- if anyone else knew about it and see what other concerns people had with the
- practice. I would have contacted you afterwards, if you hadn't decided to
- attack me first...
-
- =======================================================================
- Brian O'Neill - Systems Manager, Computer Science (508) 934-3645
- University of Massachusetts at Lowell
- Internet: oneill@ulowell.edu Moderator, comp.binaries.ibm.pc
-