home *** CD-ROM | disk | FTP | other *** search
- Newsgroups: comp.security.misc
- Path: sparky!uunet!haven.umd.edu!darwin.sura.net!spool.mu.edu!agate!doc.ic.ac.uk!cc.ic.ac.uk!imperial.ac.uk!vulture
- From: vulture@imperial.ac.uk (Thomas Sippel - Dau)
- Subject: Re: New "official" motd
- Message-ID: <1992Dec14.164652.13388@cc.ic.ac.uk>
- Keywords: motd
- Sender: vulture@carrion.cc.ic.ac.uk (Thomas Sippel - Dau)
- Nntp-Posting-Host: cscgc
- Reply-To: cmaae47@imperial.ac.uk
- Organization: Imperial College of Science, Technology and Medicine
- References: <ratner.723838076@ficus.cs.ucla.edu> <1992Dec9.014244.15480@ulysses.att.com> <jpe.723910551@ee.egr.duke.edu>
- Date: Mon, 14 Dec 92 16:46:52 GMT
- Lines: 47
-
- In article <jpe.723910551@ee.egr.duke.edu>, jpe@ee.egr.duke.edu (John P. Eisenmenger) writes:
- - While we're on this subject of the MOTD notice. Will that actually do
- - the job? What if your have .hushlogin files so they don't see the motd
- - messages when they login? What if the account an unauthorized user has
- - compromised has a .hushlogin? Wouldn't this present the intruder with
- - a legal loophole, or would s/he have given up their right to notification?
- - If the former, should we start removing .hushlogin files from our users'
- - home directories or what?
-
- Probably not, as they would be "deemed to have had notice" - just as nobody
- has yet gotten away from paying tax by claiming that they didn't know they
- had to pay because the never read their (snail-) mail.
-
- But maybe you display the notice BEFORE people log in, as we do here, viz:
-
- ====================================================
- IRIX System V.3 (cscmgb)
-
- Imperial College of Science, Technology and Medicine
-
- Centre for Computing Services
-
- This computer system is operated on behalf of
- Imperial College
-
- Only authorised users are entitled to connect and/or
- log in to this computing system. If you are not sure
- whether you are authorized, then you are not and
- should DISCONNECT IMMEDIATELY.
-
- ====================================================
-
- It also comes out for ftp connects, and is meant to rob hackers of the
- excuse that they saw a "welcome to the xxxx system" and therefore assumed
- they were authorised to use it.
-
- I don't know if it has any chance to stand up in court, but knowing what
- the lege system is like, I believe anything is possible ....
-
- Thomas
-
- --
- *** This is the operative statement, all previous statements are inoperative.
- * email: cmaae47 @ ic.ac.uk (Thomas Sippel - Dau) (uk.ac.ic on Janet)
- * voice: +44 71 589 5111 x4937 or 4934 (day), or +44 71 823 9497 (fax)
- * snail: Imperial College of Science, Technology and Medicine
- * The Center for Computing Services, Kensington SW7 2BX, Great Britain
-