[4678] in bugtraq
Re: rshd gives away usernames
daemon@ATHENA.MIT.EDU (David Holland)
Fri Jun 13 21:37:07 1997
Date: Fri, 13 Jun 1997 16:06:23 -0400
Reply-To: David Holland <dholland@EECS.HARVARD.EDU>
From: David Holland <dholland@EECS.HARVARD.EDU>
To: BUGTRAQ@NETSPACE.ORG
In-Reply-To: <199706131703.MAA03208@apollo.jeeves.net> from
"repayne@jeeves.net" at Jun 13, 97 12:01:32 pm
> On Fri, 13 Jun 1997 07:17, David Holland said:
> > Try 'rsh victimhost -l realuser' and 'rsh victimhost -l nosuchuser'.
> > The error reported is different.
I meant, of course, 'rsh victimhost -l realuser ls' and 'rsh
victimhost -l nosuchuser ls'. Otherwise it runs rlogin, and rlogind
doesn't seem to have the bug.
Sorry about the confusion.
--
- David A. Holland | VINO project home page:
dholland@eecs.harvard.edu | http://www.eecs.harvard.edu/vino