home *** CD-ROM | disk | FTP | other *** search
- Newsgroups: comp.security.misc
- Path: sparky!uunet!munnari.oz.au!cs.mu.OZ.AU!mrgreen
- From: mrgreen@mullian.ee.mu.OZ.AU (matthew green)
- Subject: Re: They forget rusers, was Re: reasons for disable fingerd
- Message-ID: <mrgreen.724182856@munagin>
- Sender: news@cs.mu.OZ.AU
- Organization: Computer Science, University of Melbourne, Australia
- References: <n051Hgpb2b@atlantis.psu.edu> <1992Dec2.162425.27877@telebit.com> <1992Dec9.173938.8706@nntp.hut.fi> <Bz3y3E.Jyu@avalon.nwc.navy.mil>
- Date: Sat, 12 Dec 1992 17:54:16 GMT
- Lines: 21
-
- dejesus@archimedes.nwc.navy.mil (Francisco X DeJesus) writes:
-
- >In article <1992Dec9.173938.8706@nntp.hut.fi> jkp@cs.HUT.FI (Jyrki Kuoppala) writes:
- >>In article <1992Dec2.162425.27877@telebit.com>, bjork@telebit (Steven Bjork) writes:
- >>>Those that disable finger often forget that nice rpc package
- >>>originating with a Big workstation vendor.
- >>
- >>and enabled by default on OS's by a couple of other vendors.
- >>
- >>>So even if they
- >>>disable finger, crackers could just run rusers.
-
- >Still, doesn't rusers (and rup, rlogin, rsh, etc) require a hostname? If
- >they don't work with IP addresses (they way finger/telnet can) then their
- >use is restricted if the machine you are trying to "probe" isn't registered.
- >Anyone know of a way around this (other than making a local entry in your
- >hosts file)?
-
- Um.. rusers with an IP number works fine.. at least it does for me.
-
- Matt..
-