Re: overcome NIS



On Sat, 03 Dec 2005 00:05:10 +0000, John Thompson wrote:

> AFAIK, NIS doesn't transmit passwords over the network,

It does when changeing passwords (although there are workarounds to this,
ofcource.)

> just the hashes

Which i'd still consider rather risky ...

> so each machine can use the hashes to authenticate.

/Only/ to autenticate users against! (Master and slave servers don't
autenticate eachother at all, nor do they clients, or clients them.)

> If someone has the access to sniff these NIS exchanges

Let me guess: they'll race (or MITM) the server's replys and inject
packets to put themselfs into whatever groups they like?

> to pick up the hashes,

They need not even sniff the wire for this (mitigating antisniff here.)
They'd only need administrative access to the host thier connecting to the
subnet with, and know your master and donainname ...

> there's somethimg else seriously wrong with your security that isn't
> directly related to NIS,

How so?

> and that person still needs to crack the hash (no trivial task) to find
> the password.

A matter of time (if there are many accounts, probably not much though.)

--
-Menno.

.



Relevant Pages

  • Re: cracking Y2k DC Admin password
    ... the hashes have been created, they are encrypted with a DES variant ... if you have the SAM file, you should also have taken the system file. ... anyone and you have your passwords. ... >> - rescue in windows folder and backup sam file from it, it has admin ...
    (Pen-Test)
  • Re: Password hashes
    ... There are only two hashes used for storing passwords in the Microsoft ... and there is no dedicated NTLM hash for stored passwords. ...
    (microsoft.public.windowsxp.security_admin)
  • Problems w/NIS Clients in Compat Mode
    ... I'm using OpenAFS for authentication and using NIS to push out the password maps. ... I'm using NIS compat mode, using netgroups to specify user account access to each machine. ... The problem with this is that they expire, causing the system to ask to change it (I don't want any local passwords). ... I'm specifically using NIS because it won't expire passwords; this is being controlled on the OpenAFS server side. ...
    (comp.os.linux.misc)
  • Re: Unchangeable passwords
    ... It is difficult to store hashes, ... > If somebody discloses private keys, ... demonstrated, the hard way, that about 10% of the passwords on almost ... urging to my successors to flush the variety of root access means they ...
    (comp.os.linux.security)
  • Re: Sparc Solaris NIS client Linux NIS server
    ... >> I'll check over the nsswitch.conf and verify that its right. ... >> insecurities with NIS. ... If "shadow" passwords are enabled properly, ... once I get the authentication working I will ...
    (comp.os.linux.setup)

Quantcast