Bugtraq mailing list archives
Obtaining NIS domainname from Gatorbox
From: DSacerdo () world std com (David Sacerdote)
Date: Mon, 10 Apr 1995 18:51:47 +0059 (EDT)
Gatorboxes are shipped without a user password set. Once connected to your net, it is easy to telnet to one of these things and log in with ANY id iff there is no user password set.
True
The user account can't change anything,
Not quite true: the user can add to the log files. While I have not tested this, I wouldn't be surprised if the user could place escape sequences in those logs, which could be a nuisance.
but can look at really interesting things. For example, if you have the GatorShare software running using NIS authentication, it will freely tell you what the NIS domainname is.
And quite a bit more, like the topology of your appletalk networks. David Sacerdote
Current thread:
- Re: Obtaining NIS domainname from Gatorbox Bob Rahe (Apr 10)
- <Possible follow-ups>
- Obtaining NIS domainname from Gatorbox David Sacerdote (Apr 10)
- Obtaining NIS domainname from Gatorbox Phrack Magazine (Apr 10)
- Re: Obtaining NIS domainname from Gatorbox der Mouse (Apr 12)
- Re: Obtaining NIS domainname from Gatorbox Dave Horsfall (Apr 12)
- NCSA security holes Dr. Frederick B. Cohen (Apr 13)
- Re: Obtaining NIS domainname from Gatorbox Luke Mewburn (Apr 14)
- Re: Obtaining NIS domainname from Gatorbox Matt T. Mannhardt (Apr 14)
- Hesiod (was Re: Obtaining NIS domainname from Gatorbox) Dave Horsfall (Apr 17)
- Re: Obtaining NIS domainname from Gatorbox npc () minotaur jpl nasa gov (Apr 14)
- Re: Obtaining NIS domainname from Gatorbox Jas (Apr 15)
- Re: Obtaining NIS domainname from Gatorbox Dave Horsfall (Apr 12)