never stop questioning

cpio.01.97-02-19.nis

cpio.01.97-02-19.nis
Posted Sep 23, 1999

cpio.01.97-02-19.nis

MD5 | 1e350cdd6a8c1c0ca7a654d6525a11c9

cpio.01.97-02-19.nis

Change Mirror Download
NIS/YP hole (again)

jack0 (jack0@CORINNE.MAC.EDU)
Wed, 19 Feb 1997 16:49:26 -0600

*YP/NIS/NIS+/forced-password-change security hole.*

Affected Sites:
Systems running Passwd+ or NPasswd and possibly other similar programs.
These are programs that have been developed to enable system
administrators to force users to change their passwords at set intervals
and check the passwords to make sure they use alphanumeric sequences as
opposed to common dictionary names. Although a step in the right
direction, these packages are not as secure as they seem.

Problem:
The problem lies in the program itself. To really asses blame, one can say
it is sloppy programming that causes this problem. It is useful to force
a user to change their password every so often. However, the sequence of
events that is defaulted to by some incarnations of YP/NIS is really
horrendus. Watch:

UNIX(r) System V Release 4.0 (good religous site)

login: priest
Sorry Passwd has expired
Change:

Instead of having the user enter their OLD password, the YP/NIS program is
asking for the user to enter the new password without verifying that it is
actually the authorized user that is logging in. There is no other excuse
for this except for "pretty dumb". This is not something new-- just a
subject that has yet to be explained.

[Concept by: Jack Of Snot, jack0@corinne.mac.edu]
[Edited by: Jonathan Katz, jkatz@corinne.mac.edu]

Comments

RSS Feed Subscribe to this comment feed

No comments yet, be the first!

Login or Register to post a comment

File Archive:

May 2012

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    May 1st
    37 Files
  • 2
    May 2nd
    53 Files
  • 3
    May 3rd
    33 Files
  • 4
    May 4th
    4 Files
  • 5
    May 5th
    10 Files
  • 6
    May 6th
    17 Files
  • 7
    May 7th
    19 Files
  • 8
    May 8th
    36 Files
  • 9
    May 9th
    34 Files
  • 10
    May 10th
    35 Files
  • 11
    May 11th
    20 Files
  • 12
    May 12th
    18 Files
  • 13
    May 13th
    11 Files
  • 14
    May 14th
    27 Files
  • 15
    May 15th
    58 Files
  • 16
    May 16th
    54 Files
  • 17
    May 17th
    25 Files
  • 18
    May 18th
    53 Files
  • 19
    May 19th
    9 Files
  • 20
    May 20th
    15 Files
  • 21
    May 21st
    25 Files
  • 22
    May 22nd
    32 Files
  • 23
    May 23rd
    35 Files
  • 24
    May 24th
    26 Files
  • 25
    May 25th
    25 Files
  • 26
    May 26th
    0 Files
  • 27
    May 27th
    0 Files
  • 28
    May 28th
    0 Files
  • 29
    May 29th
    0 Files
  • 30
    May 30th
    0 Files
  • 31
    May 31st
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2012 Packet Storm. All rights reserved.

close