OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
Bugtraq archives for 4th quarter (Oct-Dec) 1998: Re: More Rconsole stuff

Re: More Rconsole stuff

Dan_ThorsonNOTES.SEAGATE.COM
Fri, 9 Oct 1998 15:44:21 -0500

Chris said:
> The problem here is that Inetcfg saves the Rconsole password
> to SYS:ETC in a file named Netinfo.cfg. All users have full
> read access to this directory so anyone with a valid account
> can view the Rconsole password.  Given Simple Nomad's post,
> even if you cut and paste in....

Perhaps it's just our NWAdmin's default installation process, but none of
our SYS:ETC directories are readable by [Public].  When I browse to a SYS
volume I see "login", "mail", and "public" directories only, even though I
_know_ the ETC volume is there.

Food for thought.

dct