Insecure Default of hosts.equiv

Bernard Silver bs30 at sirius.gte.com.csnet
Wed Jan 4 09:16:09 AEST 1989


A (hopefully) harmless intrusion brought to our notice the default
/etc/hosts.equiv in 3.5 and 4.0 The default consists of a single "+",
which in this context means ALL known hosts are trusted.  An empty file
seems a much better choice.

	Bernard Silver



More information about the Comp.sys.sun mailing list