home *** CD-ROM | disk | FTP | other *** search
- Newsgroups: comp.security.misc
- Path: sparky!uunet!ulowell!cs.ulowell.edu!oneill
- From: oneill@cs.ulowell.edu (Brian 'Doc' O'Neill)
- Subject: Re: System "pleasure.com"
- Message-ID: <1992Jul30.014724.27352@ulowell.ulowell.edu>
- Sender: usenet@ulowell.ulowell.edu (News manager - ulowell)
- Organization: University of Massachusetts at Lowell Computer Science
- References: <64189@hydra.gatech.EDU> <janet.712298382@dunnart> <64632@hydra.gatech.EDU>
- Date: Thu, 30 Jul 1992 01:47:24 GMT
- Lines: 29
-
- In article <64632@hydra.gatech.EDU> gt5870c@prism.gatech.EDU (Noah White) writes:
- >In article <janet.712298382@dunnart> janet@cs.uwa.oz.au (Janet Jackson) writes:
- >>So? If you wanted this sysadmin to ftp to your account you would still have
- >>to give them your password.
- >
- > No, you are missing the point, the users give joe sysadmin an FTP request
- >which is probably batched by the sysadmin (similar to a firewall concept)
- >the requests are carried out and the files are given the proper ownerships
- >and placed in the proper user accounts on the system (at least that is how
- >I read it). Remember joe superuser can do anything to anyone's account
- >without their password.
- >
-
- Nope. Joe Superuser from foo.bar.com cannot do anything to anyone's
- account on _my_ systems without their password. This is what appears to be
- happening. Jim Luser from ubudweiser.edu requests that a file stored on
- foo.bar.com be ftp'd _to_ his account on ubudweiser.edu when available. At a
- later time, foo.bar.com ftp's the file to ubudweiser.edu and deposits it in
- Jim Luser's account. Now, how does this get accomplished without Luser
- giving away his password on ubudweiser.edu?
-
- I'm not sure if this is what happens in the case of pleasure.com, but that
- _appears_ to be what is happening, and it hasn't been denied, but they do
- deny storing passwords.
-
- =======================================================================
- Brian O'Neill - Systems Manager, Computer Science (508) 934-3645
- University of Massachusetts at Lowell
- Internet: oneill@ulowell.edu Moderator, comp.binaries.ibm.pc
-