SUMMARY: NIS Security Question

From: R.SrinivasaMoorthy (rsm@idc.tandem.com)
Date: Fri Oct 18 1996 - 15:09:33 CDT


        OK!!. Everybody proved to me that the question was Silly!!
        Yes. Once you are root, you could do any thing.This has got
        nothing todo with NIS, NIS+.

Original Question:

> This should be a very simple, silly question.
>
> We have an NIS environment with a SUNOS 4.1.4 NIS server and SunOS
> 4.1.3_U1,Linux NIS Clients with automount running.
>
> Presently from any NIS Client, as root, one can login as any user,
> by doing a "su - <user>" without specifying any password.

Many thanks to:

Nicholas R LeRoy(nick.leroy@norland.com)
Ron Loftin(rloftin@engsys.mc.xerox.com)
Jim Harm(jim@telecnnct.com)
Jochen Bern(bern@penthesilea.uni-trier.de)
Mark `Hex' Hershberger(mah@eecs.tulane.edu)
Marc S. Gibian(gibian@stars1.hanscom.af.mil)
Kevin Davidson(tkld@cogsci.ed.ac.uk)
Rich Kulawiec(rsk@itw.com)

        Thanks
        Srinivasa Moorthy
        (rsm@idc.tandem.com)
 

-- 
  Thanks
  Moorthy
  --------------------------------------------------------------------------
  | |  R.Srinivasa Moorthy    Ph: 564807/565891 [301]     		 | |
  | |  (rsm@idc.tandem.com)                                              | |
  | |                                                                    | |
  | |  We are not doing the Customer a favour by serving him,he is doing | | 
  | |  a favour by giving us an opportunity to do so - M.G.              | |
  --------------------------------------------------------------------------



This archive was generated by hypermail 2.1.2 : Fri Sep 28 2001 - 23:11:13 CDT