Re: securityhole /proc/sys/kernel/domainname

Bernd Eckenfels (ukd1@rzstud1.rz.uni-karlsruhe.de)
18 Feb 1996 08:27:47 GMT


Christoph Lameter (clameter@miriam.fuller.edu) wrote:
> this file should not be world readable. As I understand the Yellow Pages the
> domainname is a kind of password that allows NIS access.

PPL who use the nisdomainname as a passwort to protect NIS deserve to drink
warm beer and be slaped with a large trout. Every user on a System can read
the NIS/YP domainname (by getdomainname, sysctl or /proc). Have u ever typed
"nisdomainname" on the prompt?

Greetings
Bernd

-- 
  (OO)      -- Bernd_Eckenfels@Wittumstrasse13.76646Bruchsal.de --
 ( .. )  ecki@lina.{inka.de,ka.sub.org}  http://home.pages.de/~eckes/
  o--o     *plush*  2048/93600EFD  eckes@irc  +4972573817  *plush*
(O____O)       If privacy is outlawed only Outlaws have privacy