exploit the possibilities
Home Files News &[SERVICES_TAB]About Contact Add New

cpio.01.97-02-19.nis

cpio.01.97-02-19.nis
Posted Sep 23, 1999

cpio.01.97-02-19.nis

SHA-256 | f6761d4af47b65c5d3fca065709005713809049d7c272dd433801931f965247f

cpio.01.97-02-19.nis

Change Mirror Download
NIS/YP hole (again)

jack0 (jack0@CORINNE.MAC.EDU)
Wed, 19 Feb 1997 16:49:26 -0600

*YP/NIS/NIS+/forced-password-change security hole.*

Affected Sites:
Systems running Passwd+ or NPasswd and possibly other similar programs.
These are programs that have been developed to enable system
administrators to force users to change their passwords at set intervals
and check the passwords to make sure they use alphanumeric sequences as
opposed to common dictionary names. Although a step in the right
direction, these packages are not as secure as they seem.

Problem:
The problem lies in the program itself. To really asses blame, one can say
it is sloppy programming that causes this problem. It is useful to force
a user to change their password every so often. However, the sequence of
events that is defaulted to by some incarnations of YP/NIS is really
horrendus. Watch:

UNIX(r) System V Release 4.0 (good religous site)

login: priest
Sorry Passwd has expired
Change:

Instead of having the user enter their OLD password, the YP/NIS program is
asking for the user to enter the new password without verifying that it is
actually the authorized user that is logging in. There is no other excuse
for this except for "pretty dumb". This is not something new-- just a
subject that has yet to be explained.

[Concept by: Jack Of Snot, jack0@corinne.mac.edu]
[Edited by: Jonathan Katz, jkatz@corinne.mac.edu]
Login or Register to add favorites

File Archive:

April 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Apr 1st
    10 Files
  • 2
    Apr 2nd
    26 Files
  • 3
    Apr 3rd
    40 Files
  • 4
    Apr 4th
    6 Files
  • 5
    Apr 5th
    26 Files
  • 6
    Apr 6th
    0 Files
  • 7
    Apr 7th
    0 Files
  • 8
    Apr 8th
    22 Files
  • 9
    Apr 9th
    14 Files
  • 10
    Apr 10th
    10 Files
  • 11
    Apr 11th
    13 Files
  • 12
    Apr 12th
    14 Files
  • 13
    Apr 13th
    0 Files
  • 14
    Apr 14th
    0 Files
  • 15
    Apr 15th
    30 Files
  • 16
    Apr 16th
    10 Files
  • 17
    Apr 17th
    22 Files
  • 18
    Apr 18th
    45 Files
  • 19
    Apr 19th
    0 Files
  • 20
    Apr 20th
    0 Files
  • 21
    Apr 21st
    0 Files
  • 22
    Apr 22nd
    0 Files
  • 23
    Apr 23rd
    0 Files
  • 24
    Apr 24th
    0 Files
  • 25
    Apr 25th
    0 Files
  • 26
    Apr 26th
    0 Files
  • 27
    Apr 27th
    0 Files
  • 28
    Apr 28th
    0 Files
  • 29
    Apr 29th
    0 Files
  • 30
    Apr 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2022 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close