Re: why does telnetd run as root?

From: Joerg Wunsch (j@ida.interface-business.de)
Date: 08/31/01


Date: Fri, 31 Aug 2001 13:37:49 +0200
From: Joerg Wunsch <j@ida.interface-business.de>
To: Garrett Wollman <wollman@khavrinen.lcs.mit.edu>

As Garrett Wollman wrote:

> <<On Thu, 30 Aug 2001 20:11:02 +0200, Joerg Wunsch <j@ida.interface-business.de> said:
>
> > But then, it's IMHO much safer to run telnetd as user
> > `daemon', and have login(1) allow user daemon to pass -h.
>
> Only works for cleartext password authentication.

Not really, but you're right, it doesn't work for SRA telnet. It
works for anything that can be handled by /usr/bin/login, i just
tried OPIE which does well.

Still, allowing this as an option seems useful to me. (If i want
encryption, i'll use ssh anyway. Telnet is only a fallback if no
encryption is available for whatever reason. It is very unlikely i'll
find a client that could do SRA telnet but could not do ssh.)

-- 
J"org Wunsch					       Unix support engineer
joerg_wunsch@interface-systems.de        http://www.interface-systems.de/~j/
To Unsubscribe: send mail to majordomo@FreeBSD.org
with "unsubscribe freebsd-security" in the body of the message


Relevant Pages

  • RE: Commentary on the seven words
    ... When I was an operating systems programmer we all too often forgot that the Operating system existed to support the application, not the other way around. ... A Because the application that we run uses a telnet client that doesn't support ssh - and that's why I can't run ssh on this system. ... I administrate one system that has 128 clients on it and it's ...
    (RedHat)
  • Re: Commentary on the seven words
    ... A Because the application that we run uses a telnet client that doesn't ... support ssh - and that's why I can't run ssh on this system. ... General Red Hat Linux discussion list ... >operating system and utility advice and assistance and there are SEVEN ...
    (RedHat)
  • Re: SSH with no crypt
    ... i think ssh without encryption would be telnet, ... > I have readen that an old version of ssh can establish communcation ... > encryption ??? ... > Si vous avez reçu cet email par erreur,détruisez-en le contenu. ...
    (SSH)
  • FW: Telnet Security Question for a Router.
    ... Encryption has two options: none or DES ... Telnet Security Question for a Router. ... Most of the Cisco routers suport SSH, especially if you are running an IOS ...
    (Security-Basics)
  • Re: Commentary on the seven words
    ... routinely asked to help with enabling rsh and telnet. ... Shoot, I use SSH & all that, but if I wanted to allow it for some ... > I wrote in with a complaint that Linux will allow a process (like Tar, ... I administrate one system that has 128 clients ...
    (RedHat)