delorie.com/archives/browse.cgi   search  
Mail Archives: cygwin/2000/08/09/19:55:12

Mailing-List: contact cygwin-help AT sourceware DOT cygnus DOT com; run by ezmlm
List-Subscribe: <mailto:cygwin-subscribe AT sources DOT redhat DOT com>
List-Archive: <http://sources.redhat.com/ml/cygwin/>
List-Post: <mailto:cygwin AT sources DOT redhat DOT com>
List-Help: <mailto:cygwin-help AT sources DOT redhat DOT com>, <http://sources.redhat.com/ml/#faqs>
Sender: cygwin-owner AT sources DOT redhat DOT com
Delivered-To: mailing list cygwin AT sources DOT redhat DOT com
Message-ID: <30307088.965865271893.JavaMail.imail@neon.excite.com>
Date: Wed, 9 Aug 2000 16:54:30 -0700 (PDT)
From: Bob Heckel <BHeckel AT excite DOT com>
Reply-To: <bheckel AT excite DOT com>
To: cygwin AT sources DOT redhat DOT com
Subject: RE: inetd security hole?
Cc: robert DOT collins AT itdomain DOT com DOT au
Mime-Version: 1.0
X-Mailer: Excite Inbox
X-Sender-Ip: 165.247.160.21

Hi Corinna,

Yesterday night (Tues, Aug 8, 2000) Robert Collins
improved my original version.  You might want to
consider merging this version during your next update.
Thanks.

"Please be aware that if you have created your
/etc/passwd via mkpasswd -l then you may have a
security hole. 

If your PC has 'Guest' enabled in order to allow shares
to certain directories on your W2K or NT box, your
passwd file contains an entry for Guest that will allow
anyone to ftp, telnet, etc. to your machine simply by
using user guest and pressing enter for the password.
One solution is to disable the Guest account via User
Manager (NT) or Control Panel - Users and passwords
(W2K), the other is to delete the Guest entry in
/etc/passwd. 

This problem is a weakness in Windows, not Cygwin." 

Bob Heckel


> Thanks, I have checked that into the README with slight
> changes to mention anonymous ftp in that context. 
> 
> However, I will upload another version of inetutils
> this week since 
> I found a problem with anonymous ftp. 
> 
> Corinna





_______________________________________________________
Say Bye to Slow Internet!
http://www.home.com/xinbox/signup.html


--
Want to unsubscribe from this list?
Send a message to cygwin-unsubscribe AT sourceware DOT cygnus DOT com

- Raw text -


  webmaster     delorie software   privacy  
  Copyright © 2019   by DJ Delorie     Updated Jul 2019