home *** CD-ROM | disk | FTP | other *** search
- Newsgroups: comp.sys.next.misc
- Path: sparky!uunet!ukma!darwin.sura.net!zaphod.mps.ohio-state.edu!menudo.uh.edu!usenet
- From: sears@tree.egr.uh.edu (Paul S. Sears)
- Subject: Re: Password file
- Message-ID: <1992Nov9.191418.28241@menudo.uh.edu>
- Sender: usenet@menudo.uh.edu (USENET News System)
- Nntp-Posting-Host: thanatos.egr.uh.edu
- Reply-To: sears@tree.egr.uh.edu
- Organization: University of Houston
- References: <BxBIwK.97H@news.cso.uiuc.edu>
- Date: Mon, 9 Nov 1992 19:14:18 GMT
- Lines: 37
-
- In article <BxBIwK.97H@news.cso.uiuc.edu> jeffo@uiuc.edu (J.B.
- Nicholson-Owens) writes:
- =>Douglas Floyd writes
- =>> Is the NeXT Password file shadowed, or can anybody who logs on/ftps/
- =>> telnets onto your system obtain the password file so they can
- =>> run crack on it and find more ways to break in?
- =>
- =>The NeXT password file is not shadowed accessible without even having an
- =>account on the system. You can do remote nidumps of someone else's password
- =>file. Unfortunately making one's password information secure seems to be
- hard
- =>(if not impossible) without changing a MAJOR portion of the operating system
- =>(or at least this is what I was told by people on comp.sys.next.* when I
- asked
- =>a similar question).
- =>
- =>Secure passwords that crack cannot decipher seem to be the best protection
- =>against one's net-connected NeXT being broken into.
- =>--
- =>-- Jeff (jeffo@uiuc.edu)
- =>-- NeXTmail welcome
-
- (valid for 2.x and 3.0)
-
- Check out the trusted_networks property under the Securing NetInfo section of
- the Sysadmin book. By having this property enabled, the netinfo master for
- the protected domain will not grant access to information in its netinfo if a
- host's ip doesn't match the mask correctly. What is nice about this property
- is that it really works...
-
- --
- Paul S. Sears * sears@uh.edu (NeXT Mail OK)
- The University of Houston * suggestions@tree.egr.uh.edu (NeXT
- Engineering Computing Center * comments, complaints, questions)
- NeXT System Administration * DoD#1967 '83 NightHawk 650SC
- >>> SSI Diving Certification #755020059 <<<
- "Programming is like sex: One mistake and you support it a lifetime."
-