[4678] in bugtraq

home help back first fref pref prev next nref lref last post

Re: rshd gives away usernames

daemon@ATHENA.MIT.EDU (David Holland)
Fri Jun 13 21:37:07 1997

Date: 	Fri, 13 Jun 1997 16:06:23 -0400
Reply-To: David Holland <dholland@EECS.HARVARD.EDU>
From: David Holland <dholland@EECS.HARVARD.EDU>
To: BUGTRAQ@NETSPACE.ORG
In-Reply-To:  <199706131703.MAA03208@apollo.jeeves.net> from
              "repayne@jeeves.net" at Jun 13, 97 12:01:32 pm

 > On Fri, 13 Jun 1997 07:17, David Holland said:
 > > Try 'rsh victimhost -l realuser' and 'rsh victimhost -l nosuchuser'.
 > > The error reported is different.

I meant, of course, 'rsh victimhost -l realuser ls' and 'rsh
victimhost -l nosuchuser ls'. Otherwise it runs rlogin, and rlogind
doesn't seem to have the bug.

Sorry about the confusion.

--
   - David A. Holland             |    VINO project home page:
     dholland@eecs.harvard.edu    | http://www.eecs.harvard.edu/vino

home help back first fref pref prev next nref lref last post