RE: Access to well-known ports on Win2K

From: Rangan, Govindaraj (govindr@ti.com)
Date: 10/31/02


From: "Rangan, Govindaraj" <govindr@ti.com>
To: "'focus-ms@securityfocus.com'" <focus-ms@securityfocus.com>
Date: Thu, 31 Oct 2002 10:29:16 +0530

Hi All,
            Greetings.
            Do all users on Win2K have access to the well-known ports? This
question arose when I was doing some security tests in a heterogeneous
environment with Windows and Solaris boxes. Solaris RSHD's only security is
that before allowing access, it checks the source host and source tcp port.
The host should be in hosts.equiv or .rhosts and the source tcp port should
be one of well known ports (0-1023). The rsh client is a setuid script and
starts as root. However on Windows 2000, it is possible for any user (not
necessarily an admin user) to open a "well known port" to connect to any
rshd.
            Can we restrict access to well known ports to a certain user or
group? If not, the secure way is that Solaris hosts shouldn't trust Windows
hosts. Your help in resolving this is highly appreciated.
 
Regards,
Govind



Relevant Pages

  • Re: How could Install Solaris V10 into my PC with Windows XP Professional
    ... Since Solaris can mount NTFS ... And Windows can't mount ufs or zfs at all. ... install Solaris-10 or better yet Open Solaris and then install VMware ... You seem to be on the wrong track, there is no Host support in VMware ...
    (comp.unix.solaris)
  • Re: Solairs TCP/IP Networking
    ... Solaris does not know nor care what you ... If you had been paying attention, you would have noticed that the OP was having problems connecting FROM his Windows box! ... If his Solaris box is not listed in DNS, the host file is the only way he will ever connect to it by name from a Windows machine! ... , I cannot do that right...so thought if I had a hostname, I can ...
    (comp.unix.solaris)
  • Re: How could Install Solaris V10 into my PC with Windows XP Professional
    ... Since Solaris can mount NTFS ... And Windows can't mount ufs or zfs at all. ... install Solaris-10 or better yet Open Solaris and then install VMware ... You seem to be on the wrong track, there is no Host support in VMware ...
    (comp.unix.solaris)
  • Re: Solairs TCP/IP Networking
    ... Solaris does not know nor care what you ... having problems connecting FROM his Windows box! ... the host file is the only way he will ever connect to it by name ... , I cannot do that right...so thought if I had a hostname, I can ...
    (comp.unix.solaris)
  • Re: FTC Complaint filed
    ... I am playing around with Solaris and zones, and attempting to run the DOS/Win3.1,'95/98/98SE apps, each in it's own zone if needed, using WINE. ... There's nothing wrong with COBOL but there are a lot of alternatives better suited for quick-and-dirty programming on the PC. ... I have long said, in my opinion and pre-Vista, that Windows 95 was the best OS Microsoft ever made. ...
    (microsoft.public.windowsmedia.player)