We are having a strange problem on one of our Alphastations running DU 4.0b (PL Jumbo7):
a telnet to that machine will accept any valid user account but without passwd-checking !!!
in words:
telnet station1.domain.com
[...]
login: <valid_username>
passwd:<JUST <CR>>
and you're logged in !!!!!
Beleive me - this is not a very nice feeling ...
I have already checked for the /usr/sbin/telnetd, /etc/passwd files - permissions & cksums - I can't find any differences between a properly set-up machine and this dangerous beast!
Any hints?
(We have tcp_wrappers_7.5 installed, but this shouldn't make any differences, should it?)
Thanks,
Torsten
--
* torsten mohrbach
* mpi for human development ~ center for adaptive behavior and cognition
* lentzealle 94 ~ 14195 berlin ~ germany
* phone: (+49) 30 82406-351 ~ fax: (+49) 30 82406-394
* net: mohrbach_at_mpib-berlin.mpg.de ~ http://www.mpib-berlin.mpg.de/abc
Received on Tue Oct 27 1998 - 08:50:14 NZDT