Save construction?

Save construction?

Post by Y. v.d. Ber » Thu, 02 Oct 1997 04:00:00



Hello all,

I'm using a rsh in a construction of which I'm not sure wheather it
involves some security risks or not. The 'construction':
A cgi script on a Linux (web)server starts a sql script on an other
trusted host using rsh. The cgi user is 'nobody'.
The sql-script runs under a different user (on the other host).
In the .rhosts file I authorized nobody for rsh.

I was wondering if it might be easy for somebody to use nobody
to gane access to the database on the other host. The nobody
account is the Linux default, with an * in the encrypted password
field in the passwd file.

As you can see I'm not to familiar with this stuff.

Thanks,
Yves

 
 
 

Save construction?

Post by William R. Matti » Thu, 02 Oct 1997 04:00:00



> Hello all,

> I'm using a rsh in a construction of which I'm not sure wheather it
> involves some security risks or not. The 'construction':
> A cgi script on a Linux (web)server starts a sql script on an other
> trusted host using rsh. The cgi user is 'nobody'.
> The sql-script runs under a different user (on the other host).
> In the .rhosts file I authorized nobody for rsh.

> I was wondering if it might be easy for somebody to use nobody
> to gane access to the database on the other host. The nobody
> account is the Linux default, with an * in the encrypted password
> field in the passwd file.

> As you can see I'm not to familiar with this stuff.

> Thanks,
> Yves

I would think that it would be preferable to use cgi-wrap the execute
the cgi script(s) as a user that then rsh's to the other system. I took
this approach after convincing myself that the other was just too risky.

Regards
Bill

PS: If you need cgi-wrap and can't find it via a search engine let me
know and I will mail it to you.

--
William R. Mattil       | Fred Astaire wasn't so great.

(972) 256-3219          | and... in high heels.

 
 
 

1. how linus saved (is saving my finals)

Here I am trying to print my presentation and study sheets for the final
tomorrow...
Starting win2000 box, plug the printer, which was previously plugged
into the router, which I gave to my girlfriend, windows finds new
hardware, tells me it is set up...

So, to make a long story short, I re-installed, uninstalled, updated for
about an hour.  5 reboots ( yes, I counted) still no result.

What do I do next...? Linux, red hat 8.. my test machine
I swear by god... about 1-2 minutes, no reboots, and I am printing my
papers as I write this.
And they say Linux does not support hardware.
BY the way printer is  a very common, Epson 880 Color Stylus

Well, guess which computr will SUSE this weekend?
It ain't gonna be Window$!!!

later

2. uuencoded SATAN distribution

3. "Quit and save - Exit and don't save" why?

4. panic: kmem_free

5. "Save Desktop to new.xinitrc" won't save...

6. q

7. KDE Session save: no save as default

8. make??????

9. Wiring New Construction

10. getting around passwd construction constraints.

11. Destructor called with out construction

12. Proper Password Construction Techinques

13. GNOME themes construction