home *** CD-ROM | disk | FTP | other *** search
- Path: sparky!uunet!mcsun!sunic!corax.udac.uu.se!news.uu.se!zot
- From: zot@groucho.csd.uu.se (Thomas Ljungberg)
- Newsgroups: comp.sys.mac.system
- Subject: Re: AppleShare 3.0 security hole
- Date: 18 Nov 92 11:51:40
- Organization: Computing Science Dept, Univ. of Uppsala, Sweden
- Lines: 40
- Message-ID: <ZOT.92Nov18115140@groucho.csd.uu.se>
- References: <ARIE.92Nov16100809@quip.eecs.umich.edu> <BxtK7G.4o5@news.cso.uiuc.edu>
- NNTP-Posting-Host: groucho.csd.uu.se
- In-reply-to: tinsel@uiuc.edu's message of Mon, 16 Nov 1992 17:21:13 GMT
-
- In article <BxtK7G.4o5@news.cso.uiuc.edu> tinsel@uiuc.edu (Thomas Aaron Insel) writes:
- &
- & arie@eecs.umich.edu (Arie Covrigaru) writes:
- & > There is a security hole in the AppleShare 3.0 password scheme.
- & > Suppose I am a user (or even if I am not) on an AppleShare server,
- & > but don't have administrator privileges. The following procedure will
- & > enable me to assign them to myself and thus have future access to all
- & > folders on the server.
-
- & > 1. Turn off the server.
- & > 2. Move the Users & Groups Data File file from the Preferences folder
- & >& within the system folder to the root level of the system folder.
- & > 3. Open the administrator application. The administrator will allow you
- & >& to set a new administrator password.
- &
- & This isn't a security hole in AppleShare, it's a security hole in your
- & site. If everything was layed out correctly, the server would be locked
- & in a room where you couldn't get to it.
-
- Indeed physical access to the server should be resticted, but the Admin
- password is an extra security measure. Without it, a user who managed to
- get physical access to the server for just a few minutes could change
- his/her privileges permanently. If the procedure descibed above actually
- works, the purpose of having an Admin password is lost.
-
- & At the very least, its floppy
- & drive should be locked so you can't boot into the Finder and do this sort
- & of stuff.
- That will have no effect for AppleShare version 3.0. You don't need a
- floppy to get to the Finder there. Just click on the desktop...
-
- --
-
- ---------------------------------------------------------------------------
- ,-----, ! Thomas Ljungberg,
- / -+- Computing Science Dept.,
- / .--. ! Uppsala University, Phone: +46-18-181035
- / ! ! ! Box 311,
- / '--' ! S-751 05 Uppsala, zot@csd.uu.se
- '-----------' SWEDEN
-