Bugtraq mailing list archives

Re: rshd gives away usernames


From: dholland () EECS HARVARD EDU (David Holland)
Date: Fri, 13 Jun 1997 16:06:23 -0400


On Fri, 13 Jun 1997 07:17, David Holland said:
Try 'rsh victimhost -l realuser' and 'rsh victimhost -l nosuchuser'.
The error reported is different.

I meant, of course, 'rsh victimhost -l realuser ls' and 'rsh
victimhost -l nosuchuser ls'. Otherwise it runs rlogin, and rlogind
doesn't seem to have the bug.

Sorry about the confusion.

--
   - David A. Holland             |    VINO project home page:
     dholland () eecs harvard edu    | http://www.eecs.harvard.edu/vino



Current thread: