Re: (PM) SECURITY PROBLEM.

Jeff Haas (jmh@mail.msen.com)
Thu, 9 Jul 1998 15:41:01 -0400

On Thu, Jul 09, 1998 at 11:38:38AM -0700, Chad Scott wrote:
> Sometimes things blow up on the PM3 that don't blow up on the PM2 and
> knowing that helps us find the problem.

I agree. What I disagree with is the first-line people not taking
N/A as an answer.

> On some occasions the documentation is different depending on platform.
> It's better to go at a problem with too much information than too little.

The problem appears to be the front-line people aren't given enough
options. My "platform" may very well be telnet. I've gotten people
who wont take that as an answer.

One of my other favorite stories is calling up to get a modem connect
problem diagnosed and they insisted on knowing what version of
RADIUS I was running.

I would much rather file my errata reports with the support address,
but this seems to get much less attention than phoning in and opening
a ticket. It takes less time to cave-in and give them what they want
then to ask to talk to a supervisor to get the first-line people educated.

Back to the issue at hand: If Lucent RABU hasn't done a comprehensive
security check on issues such as this, or the security of the
undocumented protocol used by pminstall et al, it should do so.
Otherwise, someone else is going to beat you to the punch and post
the results to bugtraq. I would rather that not happen.

So... when are we going to get a challenge login option to our
!root logins? I know better than to ask for ssh (unless the
other NAS makers put it in first) but I can wish...

(BTW: http://www.livingston.com/Tech/Docs/Config/Config.TOC.html is broken)

> Chad Scott
> Beta Engineer
> Lucent Technologies

-- 
Jeffrey Haas -+- jmh@msen.com -+- http://www.msen.com/~jmh 
/\/\sen, Inc. "Michigan's Best Run Internet Service Provider."
-
To unsubscribe, email 'majordomo@livingston.com' with
'unsubscribe portmaster-users' in the body of the message.
Searchable list archive: <URL:http://www.livingston.com/Tech/archive/>