Newsgroups: comp.os.vms
From: davi...@alpha2.mdx.ac.uk
Date: Tue, 3 Jul 2007 13:18:24 +0000 (UTC)
Local: Tues, Jul 3 2007 9:18 am
Subject: Re: VMS security vulnerability (POP server)
In article <op.tut97bj98vl...@murphus.linden>, "Tom Linden" <tom-rem...@kednos.com> writes: Telnet in this instance is just being used to setup a connection to the POP >On Sun, 01 Jul 2007 23:00:44 -0700, JF Mezei = ><jfmezei.spam...@vaxination.ca> wrote: >> Michael Moroney wrote: >>> attacks is the ability to sense a breakin attempt and deny access fro= >>> tried) >> Brute force. And VMS is even worse: >> $ telnet/port=3D110 chain >> up sinc> >> So by checking whether the USER command returns an -ERR or +OK, you ca= >> narrow down which usernames are valid, and then proceed to guess their= >> passwords by brute force. >What happens if you disable telnet and only allow ssh? server port and then to pass the same commands that a pop client would send. Telnet is often used in this manner. The telnet connection could come from anywhere and the only way to stop telnet connections to the POP server port would basically be to stop anyone connecting to that port eg not to run the POP server. David Webb >-- = >PL/I for OpenVMS You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
| ||||||||||||||