home *** CD-ROM | disk | FTP | other *** search
- Newsgroups: comp.sys.mac.system
- Path: sparky!uunet!ukma!wupost!uwm.edu!ux1.cso.uiuc.edu!news.cso.uiuc.edu!uxa.cso.uiuc.edu!tai50080
- From: tinsel@uiuc.edu (Thomas Aaron Insel)
- Subject: Re: AppleShare 3.0 security hole
- References: <ARIE.92Nov16100809@quip.eecs.umich.edu>
- Message-ID: <BxtK7G.4o5@news.cso.uiuc.edu>
- Originator: tai50080@uxa.cso.uiuc.edu
- Sender: usenet@news.cso.uiuc.edu (Net Noise owner)
- Reply-To: tinsel@uiuc.edu
- Organization: Masticating Illini
- Date: Mon, 16 Nov 1992 17:21:13 GMT
- Lines: 22
-
- arie@eecs.umich.edu (Arie Covrigaru) writes:
-
- > There is a security hole in the AppleShare 3.0 password scheme.
- > Suppose I am a user (or even if I am not) on an AppleShare server,
- > but don't have administrator privileges. The following procedure will
- > enable me to assign them to myself and thus have future access to all
- > folders on the server.
-
- > 1. Turn off the server.
- > 2. Move the Users & Groups Data File file from the Preferences folder
- > within the system folder to the root level of the system folder.
- > 3. Open the administrator application. The administrator will allow you
- > to set a new administrator password.
-
- This isn't a security hole in AppleShare, it's a security hole in your
- site. If everything was layed out correctly, the server would be locked
- in a room where you couldn't get to it. At the very least, its floppy
- drive should be locked so you can't boot into the Finder and do this sort
- of stuff.
- --
- Thomas Insel (tinsel@uiuc.edu)
- s-mail: 208 Saunders, 906 West College Court, Urbana IL 61801
-