home *** CD-ROM | disk | FTP | other *** search
- Newsgroups: comp.sys.novell
- Path: sparky!uunet!s5!is1.is.morgan.com!is.morgan.com!mpiet
- From: mpiet@is.morgan.com (Mark Pietrasanta)
- Subject: Re: Hack.exe
- Message-ID: <1992Nov19.173635@is.morgan.com>
- Sender: news@is.morgan.com
- Nntp-Posting-Host: is11
- Organization: Morgan Stanley - IS
- References: <1992Nov19.120307@is.morgan.com> <7168@news.duke.edu>
- Date: Thu, 19 Nov 1992 22:36:35 GMT
- Lines: 36
-
- In article <7168@news.duke.edu>, low00001@bullnext.mc.duke.edu (Richard Low) writes:
- |> In article <1992Nov19.120307@is.morgan.com> mpiet@is.morgan.com (Mark
- |> Pietrasanta) writes:
- |> > I agree! I wrote one of the two NLM's that can be used to break into a
- |> > Novell Server. There is no plug for this, other than securing your
- |> > console so the NLM can't be loaded (via direct, RCONSOLE, or XCONSOLE).
- |> >
- |> The basic premise behind server security is physically securing the box.
- |> Getting into a server by loading an NLM is pretty simple, you just have to
- |> keep prying hands off your server. I mean, anybody can cause damage by
- |> just pulling the plug!
- |>
- |> Richard Low
-
- Yes, but the issue is damaging the data versus getting at it. It's
- a lot more damaging to actually get and read the data, especially if
- no one knows (unlike pulling the plug).
-
- This is a security hole, even if it is impossible to plug. The only
- solution is to physically secure the server. But if that level of
- security is broken, your server is completely exposed -- not just to
- physical damage, which is detectable after the fact, but to exposure
- of data which is not (really) detectable. This seems _very_ dangerous.
-
- Is there a consensus that this is or isn't a problem?
- --
- Mark Pietrasanta - mpiet@is.morgan.com
- * * * * * * * * *
-
- "Great spirits have always encountered violent opposition from
- mediocre minds." - Albert Einstein
-
- ----------------------------------------------------------------
- Disclaimer: These responses are my own and in no way reflect the
- views of my employer.
- ----------------------------------------------------------------
-