NIS password guessed via TCP

Risk Level: Medium risk vulnerability  Medium

Check or Attack Name: nistcp

Platforms: Unix
Description:

NIS passwords can be guessed through TCP by an attacker who possesses the NIS domain name.

Remedy:

For Sun Microsystems computers, apply SunOS Patch ID# 100482-08 available at http://sunsolve.sun.com/sunsolve/pubpatches/patches.html.

References:

FTP directory /pub/patches/ at sunsolve1.sun.com, SunOS 4.1.3: ypserv, ypxfrd & portmap security patch, ftp://sunsolve1.sun.com/pub/patches/100482.readme

CERT Advisory CA-97.22, BIND - the Berkeley Internet Name Daemon, http://www.cert.org/advisories/CA-97.22.bind.html


X-Force Logo
Know Your Risks