home *** CD-ROM | disk | FTP | other *** search
- Comments: Gated by NETNEWS@AUVM.AMERICAN.EDU
- Path: sparky!uunet!usc!howland.reston.ans.net!paladin.american.edu!auvm!AUDUCVAX.BITNET!OWEN
- X-Envelope-to: CWIS-L@WUVMD.BITNET
- X-VMS-To: IN%"CWIS-L@WUVMD.BITNET"
- Message-ID: <01GTTBI8LW4G0000IP@DUCVAX.AUBURN.EDU>
- Newsgroups: bit.listserv.cwis-l
- Date: Fri, 22 Jan 1993 09:14:00 CST
- Sender: "Campus-Wide Information Systems" <CWIS-L@WUVMD.BITNET>
- From: Larry Owen <OWEN@AUDUCVAX.BITNET>
- Subject: Re: CWIS, INTERNET and anonymous users!
- Lines: 50
-
- David Henry says:
-
- >What we have done here at the University of Maryland is to restrict telnet
- >access for users with anonymous access via dial-up. We know when the user is
- >coming from our dial-in pool and in that case we don't allow people to telnet
- >to anywhere outside our local domain. Otherwise, there is no restriction.
- >All that a user needs to do is access a system within our domain (this requires
- >a non-anonymous login somewhere) first and then they can use our CWIS with no
- >restrictions. Since all faculty, staff, and students can get a userid, we
- >don't see this as a terrible problem.
- >
- >This does disable some services for some users, but we felt this was necessary
- >to prevent hackers from attacking systems all over the Internet. In fact, one
- >of the reasons for implementing these restrictions was that our CWIS was being
- >used to break into other systems on the Internet. It IS unfortunate that a
- >few hackers have forced us to take this action, but I feel confident that it
- >is the right thing to do.
- >
- Not directly related to CWISes, but:
- The dialup question also begs the question about DOS machines and Macs,
- particularly in public labs, but also in offices. These machines may be
- used more or less anonymously, applications that attempt to identify
- the user (news readers and mailers) are trivial to spoof on these machines,
- there are no audit trails, etc. Do you allow these types of machines
- access to the Internet at large, or do you require logins to time-sharing
- machines first?
-
- I'll go ahead and answer the question in my own case. The terminal servers
- on our dialup facility are configured so that they can only telnet to
- machines within our class B net and our state Supercomputer net. I have
- had intentions of setting up access lists on our routers to similarly
- restrict PCs and Macs in public labs, but have never gotten around to
- it. It's becoming an issue because our computer center folks, who operate
- the news server, are grappling with the decision on whether or not to
- allow posting from PC-based news readers, and the whole question of
- anonymous access to the Internet has naturally arisen.
- >
- >I don't know what the official Internet policies are regarding anonymous access
- >to the Internet is, but it makes sense to me that it is appropriate to restrict
- >such access when it is reasonable and possible to do so.
- >
- I seem to remember reading in an RFC or FYI either a requirement or a
- strong suggestion to disallow anonymous access. However, I've just in
- the last few days spent a little time trying to locate the reference,
- and haven't been able to find it, so maybe I was hallucinating. It
- may be in the "oral tradition" FYI.
-
- Larry Owen email: owen@noc.auburn.edu or
- Campus Network Administrator owen@ducvax.auburn.edu
- Auburn University phone: (205) 844-4110
-