OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
Bugtraq Archives: gdm thing

gdm thing


Subject: gdm thing
From: Kermit the Frog (kermitTOWER.COM.AR)
Date: Sun Dec 05 1999 - 20:44:18 CST


Hello! while trying this new soft to replace the ``old'' xdm, I found out
that if a wrong passwd is supplied, gdm will answer with a ``incorrect
password'' message. So I tried to log in as an inexistent user ... the
result was "user unknown". The vulnerabilty seems trivial to me.

The version tested was gdm-2.0beta4.

Best regards.

                           Cervi~no Ulises
<kermittower.com.ar> <ulisesrosario.linux.org.ar>
...............................................................................
"Contrary to popular opinion, Unix is user friendly, It just happens to be
 very selective about who it makes friends with."



This archive was generated by hypermail 2b27 : Mon Dec 06 1999 - 12:36:43 CST