Newsgroups: comp.os.vms
From: b...@cs.uofs.edu (Bill Gunshannon)
Date: 2 Jul 2007 15:43:04 GMT
Local: Mon, Jul 2 2007 11:43 am
Subject: Re: VMS security vulnerability (POP server)
In article <op.tut97bj98vl...@murphus.linden>,
"Tom Linden" <tom-rem...@kednos.com> writes: > On Sun, 01 Jul 2007 23:00:44 -0700, JF Mezei = He is using TELNET from the source end. The destination is POP. > <jfmezei.spam...@vaxination.ca> wrote: >> Michael Moroney wrote: >>> attacks is the ability to sense a breakin attempt and deny access fro= >>> tried) >> Brute force. And VMS is even worse: >> $ telnet/port=3D110 chain >> up sinc> >> So by checking whether the USER command returns an -ERR or +OK, you ca= >> narrow down which usernames are valid, and then proceed to guess their= >> passwords by brute force. > What happens if you disable telnet and only allow ssh? If he disables TELNET he can't get out of his box. :-) Somehow, I don't think that will solve a problem with incoming POP connections. bill -- You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
| ||||||||||||||