[1442] in bugtraq
Obtaining NIS domainname from Gatorbox
daemon@ATHENA.MIT.EDU (David Sacerdote)
Tue Apr 11 04:45:12 1995
Date: Mon, 10 Apr 1995 18:51:47 +0059 (EDT)
From: David Sacerdote <DSacerdo@world.std.com>
To: bugtraq@fc.net
> Gatorboxes are shipped without a user password set. Once connected to your
> net, it is easy to telnet to one of these things and log in with ANY id
> iff there is no user password set.
True
> The user account can't change anything,
Not quite true: the user can add to the log files. While I have not
tested this, I wouldn't be surprised if the user could place escape
sequences in those logs, which could be a nuisance.
> but can look at really
> interesting things. For example, if you have the GatorShare software
> running using NIS authentication, it will freely tell you what the
> NIS domainname is.
And quite a bit more, like the topology of your appletalk networks.
David Sacerdote