Bugtraq mailing list archives

Obtaining NIS domainname from Gatorbox


From: DSacerdo () world std com (David Sacerdote)
Date: Mon, 10 Apr 1995 18:51:47 +0059 (EDT)


Gatorboxes are shipped without a user password set. Once connected to your
net, it is easy to telnet to one of these things and log in with ANY id
iff there is no user password set. 

True

The user account can't change anything, 
Not quite true: the user can add to the log files.  While I have not 
tested this, I wouldn't be surprised if the user could place escape 
sequences in those logs, which could be a nuisance.

but can look at really 
interesting things. For example, if you have the GatorShare software
running using NIS authentication, it will freely tell you what the
NIS domainname is.

And quite a bit more, like the topology of your appletalk networks.

                David Sacerdote



Current thread: