home *** CD-ROM | disk | FTP | other *** search
- Path: sparky!uunet!pmafire!news.dell.com!swrinde!gatech!usenet.ins.cwru.edu!agate!spool.mu.edu!olivea!hal.com!halaus!halaus!petonic
- From: petonic@hal.com (Michael A. Petonic)
- Newsgroups: comp.sys.sun.apps
- Subject: That's no security hole, that's my wife!
- Message-ID: <PETONIC.92Dec21133704@daisy.hal.com>
- Date: 21 Dec 92 19:37:03 GMT
- References: <1992Dec16.153218.22830@einoed.in-berlin.de> <16805@pak.UUCP>
- <1992Dec20.103222.5141@elroy.jpl.nasa.gov>
- Sender: news@hal.com
- Reply-To: petonic@hal.com (Michael A. Petonic)
- Followup-To: comp.sys.sun.apps
- Organization: Henry's Laughing Gas Co., Inc.
- Lines: 27
- In-Reply-To: earle@elroy.jpl.nasa.gov's message of Sun, 20 Dec 1992 10:32:22 GMT
-
- In article <1992Dec20.103222.5141@elroy.jpl.nasa.gov> earle@elroy.jpl.nasa.gov (Greg Earle - Gainfully Unemployed) writes:
- >Yes, "Aviator" (TM) is too good to be a video game. So they made it a
- >security hole as well.
- >
- >What do you think of a program that needs to access /dev/nit to do
- >multicasting (for Dogfight Mode), and instead of running setuid to root to
- >open() /dev/nit and then doing a setreuid() back to the real user i.d. after
- >doing so, it chmod's /dev/nit to mode 666 in the installation script?!?
- >
- >Your "Aviator" players who are happily dogfighting can then later on run
- >"etherfind" or "tcpdump" or "snoop" and happily intercept passwords at will...
-
- Disclaimer: I don't have Aviator... but regarding Greg's complaints:
-
- While it's true that their installation procedure (at least, as described
- above) is a little faulty, it's not much of an added risk to have
- workstations run etherfind, tcpdump or whatever. You can't guarantee
- security on any lan which might have promiscious mode ethernet adaptors.
- This includes a PC, or any Sniffer[tm]-like device.
-
- -pet-
- --
- Michael A. Petonic petonic@hal.com +1-512-794-2855
- HaL Computer Systems International, Ltd. -- A Bermuda Corporation
- Director of Dangerous Activities [ACK to Geoff.Kimbrough@sun.com]
- Austin, Texas
- "No balls, no blue chip."
-