Re: SECURITY PROBLEM: autofs [all versions]

2000-07-01 Thread Nathan Paul Simons
On Sat, Jul 01, 2000 at 08:55:10AM -0400, Daniel Burrows wrote: > On Sat, Jul 01, 2000 at 10:19:39AM +0200, Thor <[EMAIL PROTECTED]> was heard > to say: > ..unless, of course, the machine's owner has disabled floppy boots..in which > case, you have to open the thing up and reset the BIOS; if the

Re: SECURITY PROBLEM: autofs [all versions]

2000-07-01 Thread Nathan Paul Simons
On Sat, Jul 01, 2000 at 08:55:10AM -0400, Daniel Burrows wrote: > On Sat, Jul 01, 2000 at 10:19:39AM +0200, Thor <[EMAIL PROTECTED]> was heard to >say: > ..unless, of course, the machine's owner has disabled floppy boots..in which > case, you have to open the thing up and reset the BIOS; if the

Re: SECURITY PROBLEM: autofs [all versions]

2000-07-01 Thread Alexander Hvostov
Thor, Disable booting from floppy in BIOS, password protect LILO, install chassis intrusion detection system wired to gun turrets with 50mm heavy machine guns... ...okay, I think I'm going a little overboard here... ;) Regards, Alex. --- PGP/GPG Fingerprint: EFD1 AC6C 7ED5 E453 C367 AC7A B4

Re: SECURITY PROBLEM: autofs [all versions]

2000-07-01 Thread Alexander Hvostov
Thor, Disable booting from floppy in BIOS, password protect LILO, install chassis intrusion detection system wired to gun turrets with 50mm heavy machine guns... ...okay, I think I'm going a little overboard here... ;) Regards, Alex. --- PGP/GPG Fingerprint: EFD1 AC6C 7ED5 E453 C367 AC7A B

Re: SECURITY PROBLEM: autofs [all versions]

2000-07-01 Thread Daniel Burrows
On Sat, Jul 01, 2000 at 10:19:39AM +0200, Thor <[EMAIL PROTECTED]> was heard to say: > if you have physical access to the console and floppy drive you can always > start with a boot + root floppy, mount the hard disk and modify the > mounted /etc/passwd file ... this is an old trick, usefull whe

Re: SECURITY PROBLEM: autofs [all versions]

2000-07-01 Thread Daniel Burrows
On Sat, Jul 01, 2000 at 10:19:39AM +0200, Thor <[EMAIL PROTECTED]> was heard to say: > if you have physical access to the console and floppy drive you can always > start with a boot + root floppy, mount the hard disk and modify the > mounted /etc/passwd file ... this is an old trick, usefull whe

Re: SECURITY PROBLEM: autofs [all versions]

2000-07-01 Thread Mark Janssen
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 On Sat, 1 Jul 2000, Thor wrote: > huh ? and you call this an xploit ? > > if you have physical access to the console and floppy drive you can always > start with a boot + root floppy, mount the hard disk and modify the > mounted /etc/passwd file

Re: SECURITY PROBLEM: autofs [all versions]

2000-07-01 Thread Thor
Hi, > I'm obviously doing something wrong ... > > I've written to the maintainer of the autofs package according to the > page summary listed under 'packages' from the website, and as I also saw > somewhere else (dpkg -s listing?). I filed a bug report against autofs > and marked it as release

Re: SECURITY PROBLEM: autofs [all versions]

2000-07-01 Thread Mark Janssen
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 On Sat, 1 Jul 2000, Thor wrote: > huh ? and you call this an xploit ? > > if you have physical access to the console and floppy drive you can always > start with a boot + root floppy, mount the hard disk and modify the > mounted /etc/passwd fil

Re: SECURITY PROBLEM: autofs [all versions]

2000-07-01 Thread Thor
Hi, > I'm obviously doing something wrong ... > > I've written to the maintainer of the autofs package according to the > page summary listed under 'packages' from the website, and as I also saw > somewhere else (dpkg -s listing?). I filed a bug report against autofs > and marked it as release