Re: Gaping security hole? (network db connections)
Posted in 1997
That is quite a price. With an entry in hosts.equiv, the remote user can login as ANY user. I much prefer .rhosts, more of a pain to administer, but less of a gaping security hole. cheers j. At 07:58 PM 10/31/97 +0000, you wrote: }Nathan Neulinger wrote: }> }> Is it just me misreading things, or is there no security whatsoever in the }> network sqlexec connections to an informix DB server? }> }I'll give you the short answer. }Yes and No. }Don't use .rhosts . }Using hosts.equiv works, and you do have authentication, }however, at what price. } }-- }#include <std_disclaimer.h> /* Mike Segel (MS385) */ }#include <No_Spam.h> }#ifdef OFFENDED_BY_CONTENT }The author takes no responsibility for this post. }Any resemblence to a coherent rational thought is purely coincidence. }-The Management. }#endif }***************************** }Due to AGIS's Refusal to Act Responsibly }We are blocking all of their domains at the packet level. }This block will exist until AGIS modifies their policies to }conform to existing RFCs and net community standards. } }We encourage all ISPs and domain holders to do the same. }***************************** } }