delorie.com/archives/browse.cgi   search  
Mail Archives: cygwin/2001/01/22/09:13:41

Mailing-List: contact cygwin-help AT sourceware DOT cygnus DOT com; run by ezmlm
List-Subscribe: <mailto:cygwin-subscribe AT sources DOT redhat DOT com>
List-Archive: <http://sources.redhat.com/ml/cygwin/>
List-Post: <mailto:cygwin AT sources DOT redhat DOT com>
List-Help: <mailto:cygwin-help AT sources DOT redhat DOT com>, <http://sources.redhat.com/ml/#faqs>
Sender: cygwin-owner AT sources DOT redhat DOT com
Delivered-To: mailing list cygwin AT sources DOT redhat DOT com
Date: Mon, 22 Jan 2001 14:12:01 +0000 (GMTST)
From: Keith Starsmeare <keith_starsmeare AT yahoo DOT co DOT uk>
X-X-Sender: <kstarsm AT kampala DOT analog DOT com>
To: <cygwin AT cygwin DOT com>
Subject: rsh -l doesn't require a password
Message-ID: <Pine.CYG.4.31.0101221409310.316-100000@kampala.analog.com>
MIME-Version: 1.0

There appears to be a security problem with the inetd. I can access my
NT box via rsh remotely without giving a password if I use the -l
option to specify a valid user account:

  % rsh -l kstarsm kampala id
  uid=18(system) gid=512(domadmin) groups=512(domadmin)

As I haven't set up the hosts.equiv or .rhosts files I would hope to see:
  % rsh -l kstarsm kampala id
  Permission denied.

Keith



--
Want to unsubscribe from this list?
Check out: http://cygwin.com/ml/#unsubscribe-simple

- Raw text -


  webmaster     delorie software   privacy  
  Copyright © 2019   by DJ Delorie     Updated Jul 2019