Re: Gaping security hole? (network db connections)
Posted in 1997
I'm not getting in to this discussion if .rhosts/hosts.equiv is bad or not. I'll just comment on a factoid. As you state that anyone can play with the PC hostaddresses, connecting from a DOS/WIN/NT PC to Informix is different than connecting from a UNIX box. Last time I check the code this was very clear (which was a long time ago, 3 years or so) it was there, and if you test it, you'll see I'm right. This was introduced in OnLine 5 something I think. When connecting from a PC, the password is always validated using getpwent() or whatever the system call is, I forgot it and I'm too lazy to look it up. Now, if your end users are on PC's running SCO or UnixWare of whatever, then things are different. Rgds Karlsson BTW. I didn't read all your communication (it was a lot) so this point might have already been made. In that case, I apologize... Michael Segel wrote: [snip snip] > > -Mikey > > -- > #include <std_disclaimer.h> /* Mike Segel (MS385) */ > #include <No_Spam.h> > #ifdef OFFENDED_BY_CONTENT > The author takes no responsibility for this post. > Any resemblence to a coherent rational thought is purely coincidence. > -The Management. > #endif > ***************************** > Due to AGIS's Refusal to Act Responsibly > We are blocking all of their domains at the packet level. > This block will exist until AGIS modifies their policies to > conform to existing RFCs and net community standards. > > We encourage all ISPs and domain holders to do the same. > ***************************** -- ==================================================================== Anders Hackin' Karlsson Your friendly Database Guru Email: andersk.karlsson@karlsson.pp.se "Every time I've built character, I've regretted it" Calvin ====================================================================