Re: /etc/hosts.equiv
Posted in 1997
Roger J. Allen wrote: > > Mike Segel <mikey@segel.NOSPAM-.KING.OF.MYDOMAIN.-NOSPAM.com> wrote: > > Both the use of .rhosts and hosts.equiv are > > security holes. > > > DO NOT USE .rhosts! > > Check out your man page for rlogind. There MAY be some security > enhancements to .rhosts that your OS may have added. > Hey Roger, glad to see you at are last IGLUG meeting! [NOT!] [You should really consider joining. This years meetings will be more interesting] Sorry about that blatant plug for the Chicago Areas User Group. Caveats: 1) I just got done with PRK on my left eye (at Rush), so my patience is short and the pain is still there. 2) Reference Texts: A: UNIX System Security, David A. Curry. B: Practical UNIX Security, Simson Garfinkel and Gene Spaford. C: Network Security (Private Communication in a Public World) Kaufman, Perlman, Sspeciner Note: C doesn't deal directly with UNIX security per se, but is a good reference text for secure communication and host authentication. OK Now for the good stuff. I am going to assume that the audience knows what .rhosts is and what hosts.equiv is and how they are used by the operating system. (I know this will get me in trouble.) .rhosts are controlled by the individual users. This means that the security of the system can comprimised by an individual user. An example of this was Morris's worm. One of the attacks used was to see if the user had a .rhosts file and attack the system through that. This was used to propagate the worm to non Vaxen and SUN machines. hosts.equiv is controlled by root. This means that only root has the ability to set up *trusted* systems. The problem now becomes that instead of have just your other servers as trusted systems, you have to have you client's names or ip addresses too! Since you want to allow any and all users access from any PC, you need to place a + as the user. You could put a + + in, but then kiss your system goodbye. OSs are getting smarter and have added some additional files to track trusted systems. However hosts.equiv is the lowest denominator. I could go on, but I really need to take another T3 right now. If there is interest I could follow up this discussion. -One eyed mikey. -- #include <std_disclaimer.h> /* Mike Segel (MS385) */ #include <No_Spam.h> #ifdef OFFENDED_BY_CONTENT The author takes no responsibility for this post. Any resemblence to a coherent rational thought is purely coincidence. -The Management. #endif