Nmap Security Scanner
*Intro
*Ref Guide
*Install Guide
*Download
*Changelog
*Book
*Docs
Security Lists
*Nmap Hackers
*Nmap Dev
*Bugtraq
*Full Disclosure
*Pen Test
*Basics
*More
Security Tools
*Pass crackers
*Sniffers
*Vuln Scanners
*Web scanners
*Wireless
*Exploitation
*Packet crafters
*More
Site News
Site Search:
Exploit World
Advertising
About/Contact
Credits
Sponsors:




bugtraq logo Bugtraq mailing list archives

Re: Fwd: Re: Login Failures under Solaris 2.7
From: bpowell () ENG SUN COM
Date: Fri, 23 Feb 2001 07:39:20 -0800

okay, a side note just for clarification. Packages like ssh WILL NOT
log to loginlog, neither will a back orfice or other shell siting on
some bogus port. Only Telnet and Rsh/Rlogin will get logged this way
(possibly things like ssh compiled to use /bin/login will work as well)

This is a good feature, but doesn't stop a bad-guy only loggs the dumb ones.
Anyone wanting to bypass this will just try login four times, break the session
and re-establish a new session thus re-setting the count to five again.

Honestly folks have your customers use tokens (hard or soft)or One Time Passwords. The whole reuseable replayable 
password scheme was supposed to
be obsolete in 1979 (unix writers figured it would last 10 years, so 1968 +10
with a little fudge of a year = 1979). It is -way- past time we put it to
rest for good.

Brad


  By Date           By Thread  

Current thread:
[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]