Re: (PM) SECURITY PROBLEM.

Rick Smith (rsmith@nac.net)
Tue, 7 Jul 1998 18:35:31 -0400 (EDT)

then they know about it, and should fix it. It's a major hole, as
far as I'm concerned.

The steps to reproduce it:
Telnet to a portmaster, set debug 0x51, set cons, disconnect in
any manner

open 4 telnet sessions without logging, and one of them will most
likely contain the debug info.

On Tue, 7 Jul 1998, John Nowack wrote:

> >>> So, the next person to telnet to that portmaster, and
> >>> sit there and wait, will see all the debugging information
> >>> streamed to their screen, WITHOUT LOGGING IN.
> This has been mentioned before in the list. It seems to come up every
> now and then. Somewhere in the docs or the release note or web-site it
> used to be mentioned to always reset the console or the next person to
> telnet in *may* see the debug output. I guess it attaches the debug
> output to one of the 4 telnet sessions and if you hit the one that has
> the console attached to it, it starts spewing at you.
>
> At any rate, I know Livingston knows about this, as they have warned about
> it before.
>
> John
>
> --
> John Nowack
> john@dpc.net
> DPConsultants, Inc.
> Sys Admin -- dpc.net
> 309-925-2451
> -
> To unsubscribe, email 'majordomo@livingston.com' with
> 'unsubscribe portmaster-users' in the body of the message.
> Searchable list archive: <URL:http://www.livingston.com/Tech/archive/>
>

-
To unsubscribe, email 'majordomo@livingston.com' with
'unsubscribe portmaster-users' in the body of the message.
Searchable list archive: <URL:http://www.livingston.com/Tech/archive/>