home *** CD-ROM | disk | FTP | other *** search
- From: tar@math.ksu.edu (Tim Ramsey)
- Newsgroups: alt.security
- Subject: Re: Why does YP let me read passwd.adjunct?
- Date: 18 Jul 91 07:12:19 GMT
- Organization: Kansas State University
- Message-ID: <k8afqjINN37s@maverick.ksu.ksu.edu>
- References: <v34l_ma@rpi.edu>
-
- fitz@mml0.meche.rpi.edu (Brian Fitzgerald) writes:
-
- >Why can I do this from my machine?
-
- ># ypmatch -d notmydomain someguy passwd.adjunct.byname
- >someguy:nOtHiSrEaL.kY:::::
-
- >I was under the impression that the adjunct passwd file was supposed to
- >be "hidden" to prevent such an occurrence.
-
- Evidently Sun considers root@anywhere completely trustworthy. :-(
-
- This is exactly why I'm planning to rip NIS out, put it on tape, and hold
- a ritual burning of the tape as soon as I have some spare time. Come to
- think of it, I plan to do this to my SunOS 4.1.1 boot tapes the day after
- I get 4.4BSD up and running. :-)
-
- --
- Tim Ramsey/system administrator/tar@math.ksu.edu/(913) 532-6750/2-7004 (FAX)
- Department of Mathematics, Kansas State University, Manhattan KS 66506-2602
- student hourly no longer...
-
-