Re: unix users and radius bootstrapping (fwd)

John Capo (jc@irbs.com)
Wed, 26 Jun 1996 23:12:35 -0400 (EDT)

Craig Brozefsky writes:
>
> Well NIS is a major security bug and any high schooler would crack your
> system open if you are using it (granted they know how to use IRC and
> type "Can ewe d00ds give m3 the sk1ptz f0r NIS haxor1ng") SO I would
> suggest another method, like rdist( hah just kidding, rdist is only
> slightly more securre than NIS, which means it will take a high schooler
> at least two months int he hacking scene to aquire the scriptz for rdist
> exploitation ) or more likely your own custom deal to transfer the
> files. We use a deamon we wrote ourself to synch the files across all
> the machines.
>

NIS can be secure but not on your network.

irbs 864# rpcinfo -p dobie.ebs.net
program vers proto port
100000 2 tcp 111 portmapper
100000 2 udp 111 portmapper
100005 1 udp 675 mountd
100005 1 tcp 677 mountd
100003 2 udp 2049 nfs
100003 2 tcp 2049 nfs
150001 1 udp 680 pcnfsd
150001 2 udp 680 pcnfsd
150001 1 tcp 683 pcnfsd
150001 2 tcp 683 pcnfsd

What rpcinfo has revealed is an exercise for the reader.

John Capo jc@irbs.com
IRBS Engineering FreeBSD Servers and Workstations
(954) 792-9551 Unix/Internet Consulting - ISP Solutions