Rsh vulnerable in hosts.equiv |
---|
Risk Level: | High | Check or Attack Name: rshequiv |
---|---|---|
Platforms: | Unix | |
Description: | Sites that have a '+' or other wildcard character in the hosts.equiv file can be accessed from remote without the attacker having to know any system passwords. |
|
Remedy: | Modify your host's trust files to not include any wildcard characters. If possible, don't use Berkley-style trust relationships, but instead use a more secure solution, such as SSH. |
|
References: | CERT Advisory CA-91.12, Trusted Hosts Configuration Vulnerability, http://www.cert.org/advisories/CA-91.12.Trusted.Hosts.Configuration.vulnerability.html |
Know Your Risks |