home *** CD-ROM | disk | FTP | other *** search
- Path: sparky!uunet!usc!zaphod.mps.ohio-state.edu!darwin.sura.net!gatech!news.ans.net!cmcl2!rlgsc.com!gezelter
- From: gezelter@rlgsc.com
- Newsgroups: comp.os.vms
- Subject: Re: Failures in system security.
- Message-ID: <1992Nov17.004401.256@rlgsc.com>
- Date: 17 Nov 92 00:44:01 EST
- References: <1duniqINNkrp@gap.caltech.edu> <1992Nov13.100241.254@rlgsc.com> <1e2e81INN9h4@gap.caltech.edu> <1992Nov16.154413.13758@ncsa.uiuc.edu>
- Organization: Robert Gezelter Software Consultant, Flushing, NY
- Lines: 36
-
- In article <1992Nov16.154413.13758@ncsa.uiuc.edu>, jsue@ncsa.uiuc.edu (Jeffrey L. Sue) writes:
- > ....
- >
- > Tell you what. You give me a PC on your network with Ethernet & DECnet,
- > and we'll just see who your VAX thinks I am. Remember, *I* am the system
- > manager for my PC/MAC/VAXstation. Thus I can look like anyone I want.
- > And if I know that your system is down, or if I can interrupt the network
- > connection between systems (place myself in the middle), I can even do
- > it without anyone knowing.
- >
- > Also, I don't think it takes PHY_IO privilege to open a network object.
- > If you know what VMS Mail expects as input from the network connection I
- > believe it's very easy in DCL to fake it out.
- >
- > --
- > -----
- > Jeff Sue
- > - All opinions are mine - (and you can't have any, nya nya nya)
- --
- Jeff,
-
- Exactly my point! Any validation scheme which starts out with
- "Believe the credentials that the person who just walked in the
- door is holding" is an incident waiting to happen. As I noted
- earlier in this thread, the fact that an incomming request
- appears to have come from a privileged user on another node is,
- for most intents and purposes, a useless piece of information.
-
- - Bob
- +--------------------------------------------------------------------------+
- | Robert "Bob" Gezelter E-Mail: gezelter@rlgsc.com |
- | Robert Gezelter Software Consultant Voice: +1 718 463 1079 |
- | 35-20 167th Street, Suite 215 Fax: (on Request) |
- | Flushing, New York 11358-1731 |
- | United States of America |
- +--------------------------------------------------------------------------+
-