[54463] in Hotline Meeting
Case 207096: Re: M66-008-2.MIT.EDU allows insecure connections
daemon@ATHENA.MIT.EDU (Angie Kelic)
Mon Apr 2 17:09:15 2001
Message-Id: <200104022108.RAA32597@nighthawk.mit.edu>
To: hotline@MIT.EDU
Reply-To: net-security@MIT.EDU
cc: net-security@MIT.EDU
Date: Mon, 02 Apr 2001 17:08:39 EDT
From: Angie Kelic <sly@MIT.EDU>
------- Forwarded Message
Return-Path: <joewelch@MIT.EDU>
Received: from central-city-carrier-station.mit.edu by po14.mit.edu (8.9.2/4.7) id QAA05973; Mon, 2 Apr 2001 16:14:18 -0400 (EDT)
Received: from melbourne-city-street.mit.edu (MELBOURNE-CITY-STREET.MIT.EDU [18.7.21.86])
by central-city-carrier-station.mit.edu (8.9.2/8.9.2) with ESMTP id QAA10475
for <net-security@mit.edu>; Mon, 2 Apr 2001 16:13:46 -0400 (EDT)
Received: from [18.53.1.183] (SSIT-106.MIT.EDU [18.53.1.183])
by melbourne-city-street.mit.edu (8.9.2/8.9.2) with ESMTP id QAA12377
for <net-security@MIT.EDU>; Mon, 2 Apr 2001 16:13:41 -0400 (EDT)
Mime-Version: 1.0
Message-Id: <p05010402b6ee8dde4189@[18.53.1.183]>
In-Reply-To: <200104021822.OAA31417@nighthawk.mit.edu>
References: <200104021822.OAA31417@nighthawk.mit.edu>
Date: Mon, 2 Apr 2001 16:13:41 -0400
To: The MIT Network Security Team <net-security@mit.edu>
From: Joseph Welch <joewelch@MIT.EDU>
Subject: Re: M66-008-2.MIT.EDU allows insecure connections
Content-Type: text/plain; charset="us-ascii" ; format="flowed"
Hi,
I am no longer the contact person for this machine. Please speak to
Athena hardware hotline.
Thanks,
Joe
>Your machine (or a machine for which you are the listed
>contact) M66-008-2.MIT.EDU (18.63.2.25)
>appears to have been set up to accept remote unencrypted
>connections. Unencrypted connections put your machine
>and all of its user accounts at risk of compromise by
>intruders.
>
>Please ensure that the information that we have on file
>for this machine is correct by examining the entry
>at: https://nic.mit.edu/bin/hostupdate
>
>If you are not the correct contact for this machine,
>please let us know by sending mail to net-security@mit.edu,
>leaving the above subject line intact, and updating the
>information at: https://nic.mit.edu/bin/hostupdate
>
>Earlier versions of Athena defaulted to allowing unencrypted
>connections. Recent changes have made encrypted connections the
>default. Machines that were upgraded from older versions of
>Athena kept their old configurations, so that people depending
>on unencrypted access didn't find their machines suddenly
>requiring encryption when they updated to the new version
>of Athena.
>
>To accept the new default settings for encrypted access:
>1. Become root on your machine
>2. Run "mkserv remote" and answer the questions that follow.
> Specifically, you must answer yes to the following question:
>
>Do you wish to require encrypted passwords on remote connections?
>
>Note: mkserv takes a long time to run on some platforms such as the
> SGIs. Please do not control-C the process, just allow it to
> finish. It may take up to 5 to 10 minutes to finish and
> exit.
>
>3. Reboot the machine.
>4. Reply to this message, leaving the above subject line intact,
> and let us know what action you have taken.
>
>If you would like to give users secure access to your machine
>via Mindterm (a java SSH client), you can download and install the
>preconfigured application from http://web.mit.edu/net-security/www/dist
>
>If you believe that your work requires unencrypted access to your
>machine, or you have further questions, please reply to this
>message leaving the above subject line intact.
>
>Thank you,
>
>The Network Security Team, MIT Information Systems
><net-security@mit.edu>
- --
Joseph M Welch
Sr. Technical Assistant
Student Services Information Technology
voice: (617) 253-9817
email: joewelch@mit.edu
------- End of Forwarded Message