Computing.Net > Forums > Solaris > NIS+ Security

Computer Problems? Computing.Net has over 1,000,000 posts about all things technology related! Over 90% answered within 24 hours! Click here to start participating now! Also, be sure to check out the New User Guide.

NIS+ Security

Reply to Message Icon

Name: NIS+ Dummy
Date: August 29, 2002 at 11:46:43 Pacific
Comment:

I just set up NIS+ on two machines and created some accounts.When I do
niscat passwd.org_dir and see the contents on my system I see the encrypted passwords of all the users.I did this as an ordinary user not as root. Is this secure? What if some body runs crack on the encrypted passwords and find the real ones? Please explain me how NIS+ is more secure than NIS.

Thanks.



Sponsored Link
Ads by Google

Response Number 1
Name: Mark M
Date: September 1, 2002 at 04:21:37 Pacific
Reply:

I'm not really up on NIS+ but to get around this problem I guess you could change the permissions on the niscat command to only allow root usage. I can't see that it would cause too much of a problem.

For people to run a crack, you'd need to have a compiler on the machine. I guess they could try to run it on a pc with the copied contents of the file, but that would only generate possible matches and they'd have to manually check.

I'm not sure of the encryption algorithm on the passwords but I'd assume it's MD5 or similar, in which case it'd take forever to crack.


0

Response Number 2
Name: deks
Date: September 6, 2002 at 18:04:18 Pacific
Reply:

NIS+ is more secure than NIS because of the way it handles user credentials. Unlike NIS if you just connect a new machine and configure it to be a client, knowing the root of that machine you'll be able to see everything on the NIS network.

On the NIS if you do this scenario, you'll be the root of the local machine itself. You won't be able to see the NIS+ network hosts.

hth.


0

Sponsored Link
Ads by Google
Reply to Message Icon

Related Posts

See More







Post Locked

This post is quite old and has been locked from receiving new replies. Please create a new posting instead.


Go to Solaris Forum Home


Sponsored links

Ads by Google


Results for: NIS+ Security

Why doesnt any one answer my Q(Nis+ www.computing.net/answers/solaris/why-doesnt-any-one-answer-my-qnis/2370.html

NIS & NIS+ www.computing.net/answers/solaris/nis-amp-nis/2354.html

NIS problem - same as John's(see below) www.computing.net/answers/solaris/nis-problem-same-as-johnssee-below/1831.html