(PM) SECURITY PROBLEM. (fwd)

MegaZone (megazone@megazone.org)
Sat, 18 Jul 1998 12:07:03 -0700 (PDT)

Once upon a time Rick Smith shaped the electrons to say...
>We've discovered a grave insecurity in ComOS*****

No, you didn't. This has a been well known for years and years. The
debugging interface is disassociated fom the telnet session. It is
simple to avoid this - TURN DEBUGGING OFF. If you lose link, reconnect,
'set console', 'set debug off', 'set debug 0x0'.

Debugging is allowed to stream BY DESGIN - you can set console to point to
any port. Like one with a printer on it, and start debugging and it will
stream there - with no connection active on the port. It doesn't treat
the telnet any different. The admin should be intelligent enough to
turn things off.

-MZ

-- 
<URL:mailto:megazone@megazone.org> Gweep, Discordian, Author, Engineer, me..
Join ISP/C Internet Service Providers' Consortium <URL:http://www.ispc.org/>
"A little nonsense now and then, is relished by the wisest men" 781-788-0130
<URL:http://www.gweep.net/>  <URL:http://www.megazone.org/>  Hail Discordia!
-
To unsubscribe, email 'majordomo@livingston.com' with
'unsubscribe portmaster-users' in the body of the message.
Searchable list archive: <URL:http://www.livingston.com/Tech/archive/>