NIS server and domain names |
---|
Risk Level: | Medium | Check or Attack Name: nisdom |
---|---|---|
Platforms: | Unix | |
Description: | The password file is obtainable from Network Information Services (NIS). If the domain name can be guessed, then the NIS server can be used to acquire password files. |
|
Remedy: | Choose a hard to guess NIS domain name and use strong password techniques:
—AND— Sun users should obtain Patch ID 100482 "SunOS 4.1.3: ypserv, ypxfrd, & portmap security patch (221709 bytes)." All Sun patches are at http://sunsolve.sun.com/sunsolve/pubpatches/patches.html. |
|
References: | CERT Advisory CA-95.17, rpc.ypupdated Vulnerability, http://www.cert.org/ftp/cert_advisories/CA-95:17.rpc.ypupdated.vul CERT Advisory CA-95.17, rpc.ypupdated Vulnerability, http://www.cert.org/advisories/CA-95.17.rpc.ypupdated.vul.html |
Know Your Risks |