[6740] in bugtraq

home help back first fref pref prev next nref lref last post

Re: Bay Networks Security Hole

daemon@ATHENA.MIT.EDU (Berislav Todorovic)
Mon May 11 18:22:31 1998

X-Envelope-To: bugtraq@netspace.org
X-Vms-To: IN%"jason@VIACCESS.NET"
Date: 	Mon, 11 May 1998 15:37:00 +0100
Reply-To: Berislav Todorovic <BERI@ETF.BG.AC.YU>
From: Berislav Todorovic <BERI@ETF.BG.AC.YU>
X-To:         jason@VIACCESS.NET
To: BUGTRAQ@NETSPACE.ORG

>> > vendor: bay networks
>> > product: bay access node/wellfleet routers

Our local BayNetworks representative - COMNET (http://www.comnet.co.yu/)
forwarded to me the following recommendations:

* FTP Daemon on the router is not enabled by default - it's good to
  leave that untouched.

* If the User level has to be made publically available, don't install
  snmp.bat on the flash image, or at least don't make it available to
  the User account. This would disallow command "show snmp" at all.

* Restrict TELNET access and especially TFTP access to the router to
  certain sites on the network only, by applying appropriate filters!

Best regards,
Beri

.-------.
| --+-- |  Berislav Todorovic, B.Sc.E.E.     | E-mail: BERI@etf.bg.ac.yu
|  /|\     Hostmaster of the YU TLD          |
|-(-+-)-|  School of Electrical Engineering  | Phone:  (+381-11) 3221-419
|  \|/     Bulevar Revolucije 73             |                   3370-106
| --+-- |  11000 Belgrade SERBIA, YUGOSLAVIA | Fax:    (+381-11) 3248-681
`-------' --------------------------------------------------------------------

home help back first fref pref prev next nref lref last post