home *** CD-ROM | disk | FTP | other *** search
- Path: sparky!uunet!news.univie.ac.at!blekul11!frmop11!barilvm!bimacs!yedidya
- From: yedidya@bimacs.BITNET (Yedidya Israel)
- Newsgroups: comp.unix.wizards
- Subject: npasswd - a security hole
- Message-ID: <4159@bimacs.BITNET>
- Date: 7 Sep 92 14:06:54 GMT
- Organization: Math department, Bar-Ilan University, Ramat-Gan, ISRAEL
- Lines: 23
-
-
- I'd like to report of a security hole caused by npasswd on a specific
- circumstance. I don't like the whole community to shout on me for
- revealing "secrets" to the crackers. So please tell me how to act, who
- to tell ?
-
- Some notes:
-
- 1. The fix is very simple.
- 2. Maybe it was already revealed before and I am not making anything
- new. I don't remember it on the net.
- 3. I already told the author and we have different opinions whether
- the fix should be internal to npasswd or external. So he refuses to
- make the fix inside.
- 4. I sent Cert a description a month ago, no answer yet.
-
- --
- Israel Yedidya, Phone: 972-3-5318682 or 972-3-5318407/8
- System Administrator, Fax: 972-3-5353325
- Math & CS Department, Email: yedidya@bimacs.cs.biu.ac.il
- Bar-Ilan University, Bitnet: yedidya@bimacs
- Ramat-Gan, ISRAEL. Uucp: ...!uunet!pucc.princeton.edu!bimacs!yedidya
- If someone proves there is no God, I'll stop being religious!
-