home *** CD-ROM | disk | FTP | other *** search
- Xref: sparky comp.sys.sgi.admin:115 comp.sys.sgi:18533
- Newsgroups: comp.sys.sgi.admin,comp.sys.sgi
- Path: sparky!uunet!zaphod.mps.ohio-state.edu!darwin.sura.net!sgiblab!sgigate!odin!twilight!zuni!anchor!olson
- From: olson@anchor.esd.sgi.com (Dave Olson)
- Subject: Re: is wide-open tftpd ever needed for install from remote?
- Message-ID: <ui2dla0@zuni.esd.sgi.com>
- Sender: news@zuni.esd.sgi.com (Net News)
- Organization: Silicon Graphics, Inc. Mountain View, CA
- References: <1992Dec24.193457.16465@u.washington.edu> <C0G7I2.JM3@helios.physics.utoronto.ca>
- Date: Wed, 6 Jan 93 21:19:38 GMT
- Lines: 36
-
- In <C0G7I2.JM3@helios.physics.utoronto.ca> sysmark@helios.physics.utoronto.ca (Mark Bartelt) writes:
-
- | Last month Dave Dittrich posted an article taking SGI to task for the
- | fact that IRIX's initial /etc/passwd includes several accounts which
- | have null passwords, a potential worry if the system is attached to a
- | network. (He's not the first to grouse about this, nor is he likely
- | to be the last.) Anyway, that discussion reminded me of yet another
- | security-related issue ...
- |
- | Section 3.2 of the IRIS Software Installation Guide ("Enabling Network
- | Access to Remote Workstations") suggests modifying inetd.conf so that
- | tftpd runs in unrestricted mode. I wonder how many people have done
- | this, and have forgotten to put tftpd back into restricted mode.
-
- That *exact* same section explictly reminds you to put it back.
- It *also* tells you how you can modify the entry to leave security
- on, but only allow a couple of directories.
-
- | But my question is, why should this ever be necessary at all? Right
- | after suggesting that the tftpd "-s ..." stuff be removed, the guide
- | tells us that we might want to consider appending "<CDdir>/dist" (or
- | whatever) to the "-s /usr/local/boot" at the end of the tftpd entry
- | in inetd.conf instead, which certainly seems preferable.
-
- Because we did *just* that first, and an amazing number of people didn't
- seem to be able to handle the typing involved ;)
-
- | Given the security worries related to a unrestricted-mode tftpd, why
- | does the documentation even suggest running it that way in the first
- | place?
-
- See above.
- --
- Let no one tell me that silence gives consent, | Dave Olson
- because whoever is silent dissents. | Silicon Graphics, Inc.
- Maria Isabel Barreno | olson@sgi.com
-