home *** CD-ROM | disk | FTP | other *** search
- Newsgroups: comp.security.misc
- Path: sparky!uunet!zaphod.mps.ohio-state.edu!darwin.sura.net!cs.ucf.edu!tarpit!tous!wap!bdixon
- From: bdixon@wap.oau.org (Bill Dixon)
- Subject: Re: New "official" motd
- Message-ID: <1992Dec11.182030.30207@wap.oau.org>
- Date: Fri, 11 Dec 1992 18:20:30 GMT
- References: <ratner.723838076@ficus.cs.ucla.edu> <1992Dec9.014244.15480@ulysses.att.com> <jpe.723910551@ee.egr.duke.edu>
- Organization: White Aluminum Products, Leesburg, FL
- Keywords: motd
- Lines: 21
-
- In article <jpe.723910551@ee.egr.duke.edu> jpe@ee.egr.duke.edu (John P. Eisenmenger) writes:
- >While we're on this subject of the MOTD notice. Will that actually do
- >the job? What if your have .hushlogin files so they don't see the motd
- >messages when they login? What if the account an unauthorized user has
- >compromised has a .hushlogin? Wouldn't this present the intruder with
- >a legal loophole, or would s/he have given up their right to notification?
- >If the former, should we start removing .hushlogin files from our users'
- >home directories or what?
- >
- >-John
-
- Why not change the login herald so that the notice is displayed at each
- login? On AIX, the herald is in /etc/security/login.cfg, and can be
- changed to anything you want (I don't know whether it's legal to
- change/remove the copyright notice, though).
-
- Wouldn't this suffice to present the notice to all users, legitimate or
- otherwise?
- --
- Bill Dixon
- bdixon@wap.oau.org
-