Re: NIS and shadow passwords
Posted in 1997
Chao Y. Din wrote: > > NIS and NIS+ on Solaris work. They do not blow the security away. [I wrote] > > However NIS kinda blows the security away. > > Can you say ypcat ? :-) > > (Although that is supposed to be fixed in NIS+ right?) Gee, under NIS, if I do a YPCAT passwd, I'm pretty sure I can get your passwd file. Now, with a room full of suns/hps/pentiums running linux, etc ... armed with crypt() (The fast one ;-) How long do *you* think it would take before I could break your passwd using brute force? Of course, I could use a dictionary first to get all the easy ones. To me, this is a security risk. Of course on suns, any sun without a stored firmware passwd, I could still do some serious damage even if NIS+ didn't allow ypcat. So, you're right, ypcat doesn't pose a security threat. ;-) (My point being security is a relative concept.) -Mikey. BTW, No, I'm not paranoid, EVERYONE *IS* out to get me 8^) -- #include <std_disclaimer.h> /* Mike Segel (MS385) */ #include <No_Spam.h> #ifdef OFFENDED_BY_CONTENT The author takes no responsibility for this post. Any resemblence to a coherent rational thought is purely coincidence. -The Management. #endif ***************************** Due to AGIS's Refusal to Act Responsibly We are blocking all of their domains at the packet level. This block will exist until AGIS modifies their policies to conform to existing RFCs and net community standards. We encourage all ISPs and domain holders to do the same. *****************************