Rsh default account accessible |
---|
Risk Level: | High | Check or Attack Name: defrsh |
---|---|---|
Platforms: | Any | |
Description: | The remote host system for this account allowed access from the scanning machine. This trust may extend to other machines, allowing an attacker to compromise security. Warning: Software that scans some Unix systems may cause the system to halt if the shutdown/shutdown or halt/halt accounts/password pairs exist. For a good security policy, these accounts should be removed, renamed, or at the very least contain a difficult to guess password. |
|
Remedy: | Examine the .rhosts file, which contains configuration information for trusted hosts. Any entries containing a + (plus sign) should be removed or commented out. |
|
References: |
Know Your Risks |