Newsgroups: comp.os.vms
From: "Tom Linden" <tom-rem...@kednos.com>
Date: Mon, 02 Jul 2007 09:14:52 -0700
Local: Mon, Jul 2 2007 12:14 pm
Subject: Re: VMS security vulnerability (POP server)
On Mon, 02 Jul 2007 08:43:04 -0700, Bill Gunshannon <b...@cs.uofs.edu>
wrote: > In article <op.tut97bj98vl...@murphus.linden>, What I meant was, can ssh be similarly exploited to attempt breakin? > "Tom Linden" <tom-rem...@kednos.com> writes: >> On Sun, 01 Jul 2007 23:00:44 -0700, JF Mezei = >> <jfmezei.spam...@vaxination.ca> wrote: >>> Michael Moroney wrote: >>>> attacks is the ability to sense a breakin attempt and deny access fro= >>>> tried) >>> Brute force. And VMS is even worse: >>> $ telnet/port=3D110 chain >>> up sinc> >>> So by checking whether the USER command returns an -ERR or +OK, you ca= >>> narrow down which usernames are valid, and then proceed to guess their= >>> passwords by brute force. >> What happens if you disable telnet and only allow ssh? > He is using TELNET from the source end. The destination is POP. > bill -- You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
| ||||||||||||||