Re: Gaping security hole? (network db connections)
Posted in 1997
Nathan Neulinger wrote: > Jack Parker <jparker@informix.com> wrote: > > At 12:24 AM 11/4/97 GMT, you wrote: > > }Actually, .rhosts is still a problem, > > } > > }It jsut narrows the hole from: > > } > > } ANY user on client can log into ANY user on server > > }to > > } ANY user on client can log into this particular user on server > > > You can specify user@host to narrow it down to a specific user from a > > specific host. > > No, it DOESN'T... That's the whole point of the hole I'm talking > about. > > If you put "user@host" into 'joe's .rhosts file - with the r'cmds, it > DOES restrict it to just user@host, but with informix, it allows ANY > userid at 'host' to connect to the database as 'joe'. > > The ONLY way it can narrow any connection down to a particular user at > the remote host is if it verifies that the connection came from a port > below <1024 (as do all the r'cmds). Since it doesn't, the connection > could have come from anyone, and it is completely trusting it. > > -- Nathan Yes and no. That's why when you make a conection, it asks you for a passwd. In this case joe's passwd. It then does a getpwent() or one of the passwd c calls which is standard in UNIX. But you don't want to allow .rhosts on a system period. -Mike