home *** CD-ROM | disk | FTP | other *** search
- Path: sparky!uunet!paladin.american.edu!darwin.sura.net!wupost!sdd.hp.com!swrinde!network.ucsd.edu!sdcc12!xm9
- From: xm9@sdcc12.ucsd.edu (richard g. adair)
- Newsgroups: comp.sys.hp
- Subject: Re: Sun Vs. HP system administration
- Summary: YP security
- Keywords: YP
- Message-ID: <37274@sdcc12.ucsd.edu>
- Date: 26 Aug 92 15:10:03 GMT
- References: <9208251944.AA15570@gadget.evb.com> <1992Aug26.052741.24845@spatial.com> <STEINAR.HAUG.92Aug26161118@delab.sintef.no>
- Sender: news@sdcc12.ucsd.edu
- Organization: Arete Associates, San Diego
- Lines: 20
- Nntp-Posting-Host: sdcc12.ucsd.edu
-
- In article <STEINAR.HAUG.92Aug26161118@delab.sintef.no> Steinar.Haug@delab.sintef.no (Steinar Haug) writes:
- >Seems to work just fine, but there are security problems:
- >
- >programs) at their leisure. Sun's patch enables you to control which hosts
- >(which IP addresses) are allowed to access your YP servers.
-
- Sun's own PC/NFS defeats this "security" with the ability of the PC
- user to change his/her IP address at will. Any user can do this, so
- think again about even such SUNisms as -root=machine in your mount
- tables. False security is worse than no security...
-
- >So, because of point 1 above, we have shut down all our HP slave servers,
- >and now use only Suns as YP servers.
-
- Let me on your net for a half hour, and I'll delete all your files
- :-) :-) :-)
-
- Tony Burzio
- Arete Associates
- San Diego, CA
-