Re: Informix/Oracle security hole?
Posted in 1994
} From daemon Thu Jul 14 14:49 CDT 1994 } From: owner-informix-distr@timtow.b1.ingr.com (Phil Perucci) } Message-Id: <philpCsxIo9.BGD@netcom.com> } Subject: Informix/Oracle security hole? } Date: Thu, 14 Jul 1994 12:00:09 GMT } Reply-To: philp@netcom.com (Phil Perucci) } Organization: NETCOM On-line Communication Services (408 261-4700 guest) } Sender: owner-informix-distr@timtow.b1.ingr.com } To: informix-list@rmy.emory.edu } X-Informix-List-To: informix-distr2@timtow.b1.ingr.com } X-Informix-List-Id: <news.7604> } } Use of Informix-Star & Informix-NET requires installation of a } gaping /etc/hosts.equiv security hole for EACH client station! } } Questions: } 1) On Informix, is there any way around this? } 2) Does Oracle have the same problem? } } } -- } ============================================================================== } Phil Perucci | "All postings are my own opinion - all comments } Systems Integrator | are intended for research/educational purposes" } ============================================================================== } For question #1 - You might try placing a "+ " in front of the node names in the /etc/hosts.equiv file. This should prevent the 'r' commands like rcmd, and rcp from being honored. It will also cause rlogin to prompt for a password, but it should allow Informix-Star to validate the connection without any trouble. Of course, I can not say for sure whether this will work for your Hardware/Software combination, but it does work quit well for me. -- -------------------------------------------------------------------------- Walter S. Tyszka | wstyszka@ingr.com I/CATS Support Administrator | 205-730-5723 Intergraph Corporation | Huntsville, Alabama --------------------------------------------------------------------------