home *** CD-ROM | disk | FTP | other *** search
- Path: sparky!uunet!munnari.oz.au!uniwa!craig
- From: craig@ec.uwa.oz.au (Craig Richmond - division)
- Newsgroups: comp.security.misc
- Subject: Re: Forging E-mail from root to get users to change passwords
- Date: 5 Nov 1992 06:49:47 GMT
- Organization: The University of Western Australia
- Lines: 36
- Message-ID: <1dag6bINNs62@uniwa.uwa.edu.au>
- References: <82930@ut-emx.uucp>
- NNTP-Posting-Host: decel.ecel.uwa.edu.au
-
- ifbb657@ccwf.cc.utexas.edu (Douglas Floyd) writes:
-
- >Knowledgable users would be *VERY* suspicious because (to by knowledge)
- >root **N-E-V-E-R** needs to know a user's password to effect changes
- >to an account or the system, but this attack could work on novice UNIX
- >users.
-
- >What is the best way to prevent/slow down this form of attack?
-
- Make it clear to all users when they are given the account the sort of
- things that they will be asked to do and the sort of things they should be
- aware of. eg a list that states.
-
- Do not change your password to anything that someone tells you to.
- Report this to your superuser.
-
- Do not mail the file /etc/passwd to people requesting it. Report them to
- your superuser.
-
- If you see something you don't think looks right. TELL SOMEONE.
-
- Don't run xwindows :-)
-
- This is by far the best way to combat this sort of problem. You can also
- install a program such as tcpd which will let you prevent telnet and
- certain other service access from non-trusted sites. You still accept mail
- from anywhere because it won't get to you otherwise, but you don't have to
- accept telnet connections from anyone you don't think needs access to your
- machine. If they can't get on, they can't do any (much) damage.
-
- Craig
- --
- Craig Richmond. Computer Officer - Dept of Economics (morning) 380 3860
- University of Western Australia Dept of Education (afternoon)
- craig@ecel.uwa.edu.au Dvorak Keyboards RULE! "Messes are only acceptable
- if users make them. Applications aren't allowed this freedom" I.M.VI 2-4
-