Re: securityhole /proc/sys/kernel/domainname

Christoph Lameter (clameter@miriam.fuller.edu)
19 Feb 1996 03:47:43 -0800


Jens Glaser (jens@warez.rhoen.de) wrote:
: Hi & Ho,

: On 16 Feb 1996, Christoph Lameter wrote:
: > this file should not be world readable. As I understand the Yellow Pages the
: > domainname is a kind of password that allows NIS access.

: You can easily obtain the domainname over the bootparam-service (if you ask
: nicely). Additonally, /var/yp usually contains a directory named after the
: domainname and is world readable.

Why would I make it accessible via bootp?
And /var/yp is only accessible by root on my system.