delorie.com/archives/browse.cgi   search  
Mail Archives: cygwin/2002/10/25/18:55:24

Mailing-List: contact cygwin-help AT cygwin DOT com; run by ezmlm
List-Subscribe: <mailto:cygwin-subscribe AT cygwin DOT com>
List-Archive: <http://sources.redhat.com/ml/cygwin/>
List-Post: <mailto:cygwin AT cygwin DOT com>
List-Help: <mailto:cygwin-help AT cygwin DOT com>, <http://sources.redhat.com/ml/#faqs>
Sender: cygwin-owner AT cygwin DOT com
Mail-Followup-To: cygwin AT cygwin DOT com
Delivered-To: mailing list cygwin AT cygwin DOT com
Message-ID: <3DB9CBC6.8C1CFB08@acm.org>
Date: Fri, 25 Oct 2002 15:55:02 -0700
From: David Rothenberger <daveroth AT acm DOT org>
X-Accept-Language: en
MIME-Version: 1.0
To: cygwin AT cygwin DOT com
Subject: Re: Problem with rsh
References: <3DB9AD4E DOT 10407 AT Salira DOT com> <3DB9C013 DOT CF6CF751 AT acm DOT org> <3DB9C44F DOT 2060606 AT Salira DOT com> <20021025224810 DOT GA282137 AT WORLDNET>

Pierre is right.  Without anything in the password field, I can rsh to
my machine as anyone without providing a password, without setting up
.rhosts files and without defining hosts.equiv.

With a value in the password field, I can still rsh, but only if I have
a .rhosts file set up and with permissions set to 644.

"Pierre A. Humblet" wrote:
> 
> On Fri, Oct 25, 2002 at 03:23:11PM -0700, Andrew DeFaria wrote:
> > David Rothenberger wrote:
> >
> > >Check your /etc/passwd file and make sure there is no entry in the
> > >password field (the second field).  You want something like this:
> > >
> > >someuser::11150:...
> > >
> > >and not something like this:
> > >
> > >someuser:unused_by_nt/2000/xp:11150:...
> > >
> > Wham! Good answer! It works!
> 
> Yes, but you have no security.
> The cygwin mechanism that logs you in when the password is empty
> is the same as with .rhosts, and different from the one
> when providing a password.
> Thus it looks like your .rhosts isn't setup properly.
> Among other things it should only be writable by you.

--
Unsubscribe info:      http://cygwin.com/ml/#unsubscribe-simple
Bug reporting:         http://cygwin.com/bugs.html
Documentation:         http://cygwin.com/docs.html
FAQ:                   http://cygwin.com/faq/

- Raw text -


  webmaster     delorie software   privacy  
  Copyright © 2019   by DJ Delorie     Updated Jul 2019