Printscreen capability? SECURITY HOLE

Keith Gabryelski ag at elgar.UUCP
Sun Aug 14 03:17:40 AEST 1988


 In article <414 at uport.UUCP> plocher at uport.UUCP (John Plocher) writes:
 >In article <510 at sysco> chapman at sco.COM (brian chapman) writes:
 >>>Is a printscreen capability available in Xenix?
 >>Yes
 >>ESC x x x	Send screen to host.
 >
 >and whenever root is logged onto the console:
 >
 >	write root < x
 >
 >This security hole is one reason that many sysadmins don't use terminals
 >with a "block mode".  Adding this to the console driver is a very subtle
 >way to compromise a system.

 This is one reason why many sysadmins have "mesg n" in their .profile.
 Piece 'o cake.

 Pax, Keith

Ps, I haven't looked into where in the news code articles get rejected
if they have less message then inclusion, but it is going to get
ripped out as soon as I have posted this article.
-- 
  "If green is all there is to be, then green is good enough for me" - ktf
[  Keith   ]  UUCP: {ucsd, cbosgd!crash, sdcsvax!crash, nosc!crash}!elgar!ag
[Gabryelski]  INET: ag at elgar.cts.com                 ARPA: elgar!ag at ucsd.edu



More information about the Comp.unix.xenix mailing list