OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
Bugtraq archives for 2nd quarter (Apr-Jun) 1995: Obtaining NIS domainname from Gatorbox

Obtaining NIS domainname from Gatorbox

Ken Weaverling (weavehopi.dtcc.edu)
Mon, 10 Apr 1995 09:12:27 -0400 (EDT)

This may be an obscure hole, but it got us and still bothers me.

Gatorboxes are shipped without a user password set. Once connected to your
net, it is easy to telnet to one of these things and log in with ANY id
iff there is no user password set. 

The user account can't change anything, but can look at really 
interesting things. For example, if you have the GatorShare software
running using NIS authentication, it will freely tell you what the
NIS domainname is.

-- 
Ken Weaverling  |*|          Computer Services, Delaware Tech College
weavedtcc.edu  |*| (My opinions are mine alone, I don't speak for the college)
================|*|                 http://www.dtcc.edu/~weave
   (Finger weavehopi.dtcc.edu for PGP key, weavessnet.com for fingerprint)