[54462] in Hotline Meeting

home help back first fref pref prev next nref lref last post

Case 207101: Re: M66-008-3.MIT.EDU allows insecure connections

daemon@ATHENA.MIT.EDU (Angie Kelic)
Mon Apr 2 17:06:48 2001

Message-Id: <200104022106.RAA32575@nighthawk.mit.edu>
To: hotline@MIT.EDU
cc: net-security@MIT.EDU
Reply-To: net-security@MIT.EDU
Date: Mon, 02 Apr 2001 17:06:20 EDT
From: Angie Kelic <sly@MIT.EDU>


------- Forwarded Message

Return-Path: <joewelch@MIT.EDU>
Received: from grand-central-station.mit.edu by po14.mit.edu (8.9.2/4.7) id QAA08713; Mon, 2 Apr 2001 16:16:24 -0400 (EDT)
Received: from melbourne-city-street.mit.edu (MELBOURNE-CITY-STREET.MIT.EDU [18.7.21.86])
	by grand-central-station.mit.edu (8.9.2/8.9.2) with ESMTP id QAA28907
	for <net-security@mit.edu>; Mon, 2 Apr 2001 16:14:06 -0400 (EDT)
Received: from [18.53.1.183] (SSIT-106.MIT.EDU [18.53.1.183])
	by melbourne-city-street.mit.edu (8.9.2/8.9.2) with ESMTP id QAA12555
	for <net-security@MIT.EDU>; Mon, 2 Apr 2001 16:14:02 -0400 (EDT)
Mime-Version: 1.0
Message-Id: <p05010403b6ee8e0249ee@[18.53.1.183]>
In-Reply-To: <200104021823.OAA31423@nighthawk.mit.edu>
References: <200104021823.OAA31423@nighthawk.mit.edu>
Date: Mon, 2 Apr 2001 16:14:03 -0400
To: The MIT Network Security Team <net-security@MIT.EDU>
From: Joseph Welch <joewelch@MIT.EDU>
Subject: Re: M66-008-3.MIT.EDU allows insecure connections
Content-Type: text/plain; charset="us-ascii" ; format="flowed"

Hi,

I am no longer the contact person for this machine.  Please speak to 
Athena hardware hotline.

Thanks,
Joe





>Your machine (or a machine for which you are the listed
>contact) M66-008-3.MIT.EDU (18.63.2.26)
>appears to have been set up to accept remote unencrypted
>connections.  Unencrypted connections put your machine
>and all of its user accounts at risk of compromise by
>intruders.
>
>Please ensure that the information that we have on file
>for this machine is correct by examining the entry
>at: https://nic.mit.edu/bin/hostupdate
>
>If you are not the correct contact for this machine,
>please let us know by sending mail to net-security@mit.edu,
>leaving the above subject line intact, and updating the
>information at: https://nic.mit.edu/bin/hostupdate
>
>Earlier versions of Athena defaulted to allowing unencrypted
>connections.  Recent changes have made encrypted connections the
>default.  Machines that were upgraded from older versions of
>Athena kept their old configurations, so that people depending
>on unencrypted access didn't find their machines suddenly
>requiring encryption when they updated to the new version
>of Athena.
>
>To accept the new default settings for encrypted access:
>1. Become root on your machine
>2. Run "mkserv remote" and answer the questions that follow.
>    Specifically, you must answer yes to the following question:
>
>Do you wish to require encrypted passwords on remote connections?
>
>Note: mkserv takes a long time to run on some platforms such as the
>	SGIs.  Please do not control-C the process, just allow it to
>	finish.  It may take up to 5 to 10 minutes to finish and
>	exit.
>
>3. Reboot the machine.
>4. Reply to this message, leaving the above subject line intact,
>    and let us know what action you have taken.
>
>If you would like to give users secure access to your machine
>via Mindterm (a java SSH client), you can download and install the
>preconfigured application from http://web.mit.edu/net-security/www/dist
>
>If you believe that your work requires unencrypted access to your
>machine, or you have further questions, please reply to this
>message leaving the above subject line intact.
>
>Thank you,
>
>The Network Security Team, MIT Information Systems
><net-security@mit.edu>

- -- 
Joseph M Welch
Sr. Technical Assistant
Student Services Information Technology
voice:  (617) 253-9817
email:  joewelch@mit.edu

------- End of Forwarded Message


home help back first fref pref prev next nref lref last post