Full Disclosure mailing list archives
Re: SMC Router safe Login in plaintext
From: Paul Schmehl <pauls () utdallas edu>
Date: Wed, 03 Sep 2003 20:09:49 -0500
--On Wednesday, September 03, 2003 17:14:04 -0500 "C. Church" <cchurch () alertlogic net> wrote:
Did you read what you just said? How many ISPs have you called where they would "Tell you what your password is"? If your ISP can tell you what your password is, let us know who it is, so we can all avoid them in the future.
SBCGlobal.net, ATT.net to name two big ones.
Answer: they don't need to know your old password to change your password. It's called permissions, and privileged access. As root, or a priveleged user, I can change anyone's password without having to know the old one.
<sarcasm mode="on">No, really? I would have never guessed.</sarcasm>
Think about it.
OK, I thought about it. Now what do I do?BTW, when I say "tell you what your password is", what I mean is something like this, "Mr. Schmehl, your password is 1234qwer. Are you sure you're typing it right?"
Doh! Paul Schmehl (pauls () utdallas edu) Adjunct Information Security Officer The University of Texas at Dallas AVIEN Founding Member http://www.utdallas.edu _______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.netsys.com/full-disclosure-charter.html
Current thread:
- SMC Router safe Login in plaintext Florian Rock (Sep 03)
- <Possible follow-ups>
- RE: SMC Router safe Login in plaintext Schmehl, Paul L (Sep 03)
- RE: SMC Router safe Login in plaintext Nathan Rotschafer (Sep 03)
- Re: SMC Router safe Login in plaintext Kim Scarborough (Sep 03)
- Re: SMC Router safe Login in plaintext C. Church (Sep 03)
- Re: SMC Router safe Login in plaintext KF (Sep 03)
- Re: SMC Router safe Login in plaintext Jeremiah Cornelius (Sep 03)
- Re: SMC Router safe Login in plaintext Irwan Hadi (Sep 04)
- Re: SMC Router safe Login in plaintext KF (Sep 04)
- Re: SMC Router safe Login in plaintext morning_wood (Sep 04)
- Re: SMC Router safe Login in plaintext Paul Schmehl (Sep 03)
- Re: SMC Router safe Login in plaintext Justin (Sep 04)
- Re: SMC Router safe Login in plaintext Nicolas Couture (Sep 05)