Linux NIS could treat '+' user as a normal login account |
---|
Risk Level: | High | Check or Attack Name: LinPlus |
---|---|---|
Platforms: | Linux | |
Description: | Some older Linux distributions had a faulty yp/NIS implementation, resulting in the yp/NIS binding user (the + account) being treated as a normal account. |
|
Remedy: | Upgrade your Linux distribution to the current version. Upgrading just your kernel is not sufficient. |
|
References: |
Know Your Risks |