NIS YPBind service |
---|
Risk Level: | Low | Check or Attack Name: ypbind |
---|---|---|
Platforms: | Any | |
Description: | The NIS ypbind service was found. NIS (Network Information Service) contains data, such as host files, password files, and e-mail aliases for entire networks. It allows a remote user to obtain copies of the NIS password map information. An attacker who possesses the NIS domain name (often set up as a derivative of the public domain name) can steal information helpful in guessing passwords and gaining unauthorized access. |
|
Remedy: | The NIS domain name should be hard to guess. |
|
References: |
Know Your Risks |