A UUCP system security checklist

Erik Naggum erik at naggum.uio.no
Fri Jul 15 07:05:35 AEST 1988


Dear Systems Administrator,

Here's a little checklist.

[ ]  Do you allow uusend from uuxqt?

[ ]  Does uuxqt run under uid uucp?

[ ]  Are your most valuable UUCP files 0600 for security?

[ ]  Are the same files owned by uucp?

[ ]  You look up the parameters to uusend, and see what you can do if
     you tell uux to do it.

[ ]  You didn't like what just occured to you.

Yours, in a safer world,
Erik Naggum
--
UUCP  --   erik at naggum.se		UNIX is not ``eunuchs'' --  
ARPA  --   enag at naggum.uio.no		in fact it's rather potent
Snail --   Naggum Software; POB 1560 VIKA; OSLO 0118; NORWAY
Phone --   +47-2-384-400 (office), +47-2-549-163 (home)

"I wasn't paranoid until that man started following me." -- me, today.



More information about the Comp.unix.wizards mailing list