Bugtraq mailing list archives
Obtaining NIS domainname from Gatorbox
From: weave () hopi dtcc edu (Ken Weaverling)
Date: Mon, 10 Apr 1995 09:12:27 -0400 (EDT)
This may be an obscure hole, but it got us and still bothers me. Gatorboxes are shipped without a user password set. Once connected to your net, it is easy to telnet to one of these things and log in with ANY id iff there is no user password set. The user account can't change anything, but can look at really interesting things. For example, if you have the GatorShare software running using NIS authentication, it will freely tell you what the NIS domainname is. -- Ken Weaverling |*| Computer Services, Delaware Tech College weave () dtcc edu |*| (My opinions are mine alone, I don't speak for the college) ================|*| http://www.dtcc.edu/~weave (Finger weave () hopi dtcc edu for PGP key, weave () ssnet com for fingerprint)
Current thread:
- Re: SATAN ATTACKS EVERYWHERE, (continued)
- Re: SATAN ATTACKS EVERYWHERE Wolfgang Ley (Apr 09)
- Re: SATAN ATTACKS EVERYWHERE Christopher Klaus (Jul 25)
- Shadowed PW file under Linux lenex (Apr 06)
- Re: Shadowed PW file under Linux Cenon B.C. Marana Jr. (Apr 07)
- Re: Shadowed PW file under Linux John F. Haugh II (Apr 09)
- Re: Shadowed PW file under OSF/1 Cenon B.C. Marana Jr. (Apr 09)
- Re: Shadowed PW file under OSF/1 Software Test Account (Apr 11)
- Sys V. shedges () cactus netinterior com (Apr 11)
- ANOTHER hole in NCSA httpd1.3R Paul Phillips (Apr 11)
- UUCP/sendmail configs.. Cenon B.C. Marana Jr. (Apr 09)
- Obtaining NIS domainname from Gatorbox Ken Weaverling (Apr 10)
- Re: Shadowed PW file under Linux Cenon B.C. Marana Jr. (Apr 07)