(PM) Security glitch in COMOS

Roy (garlic@garlic.com)
Sun, 16 Nov 1997 13:31:41 -0800

System is PM2E with COM OS 3.7.2

Someone is trying to break in by trying userid/password combinations.
COMOS seems to disconnect after three invalid tries when using the logon
prompt but this does not happen with PAP.

A user can try different userids/passwords forever in a PAP
authentication scenario.

Also note that Radius 2.01 will no log these attempts. This error is
only displayed when you have debugging turned on. I modified Radius to
add the logging and the number of attempted breakins is amazing.
To unsubscribe, email 'majordomo@livingston.com' with
'unsubscribe portmaster-users' in the body of the message.