NIS maps |
---|
Risk Level: | Low | Check or Attack Name: ypmap |
---|---|---|
Platforms: | Unix | |
Description: | NIS (Network Information Service) contains data such as host files, password files, and e-mail aliases for entire networks. It allows a remote user to obtain copies of the NIS password map information. An attacker who possesses the NIS domain name (often set up as a derivative of the public domain name) can steal information helpful in guessing passwords and gaining unauthorized access. |
|
Remedy: | Fortify the NIS domain name and use strong password techniques:
|
|
References: |
Know Your Risks |