Newsgroups: comp.os.vms
From: Tom Wade <nos...@picard.eurokom.ie>
Date: Wed, 04 Jul 2007 15:54:08 +0100
Local: Wed, Jul 4 2007 10:54 am
Subject: Re: VMS security vulnerability (POP server)
> Brute force. And VMS is even worse: The problem is that an application that accepts a username/password and attempts to validate using $HASH_PASSWORD and $GETUAI *must* also make explicit calls to $SCAN_INTRUSION, otherwise it provides a back door around the intrusion detection mechanism. I have seen this on many applications, including POP servers and web scripts to change your password. With the benefit of hindsight, it might have been a better idea to provide a $VERIFY_PASSWORD service which combines the three functions above, because it is so easy for a developer to overlook it. Another place to check is if the UCX SMTP server supports SASL (this is To check if your SMTP server supports SASL, telnet to port 25 and issue --------------------------------------------------------- You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
| ||||||||||||||