Dear Mr. Thomas,

  If you want to fix the security problems without stirring
the pot, I suggest you use an anonymous remailer to let your
bosses and the sysadmin know that your system is being compromised.

  Someone else suggested that you run TCP wrappers to log and
deny access.  I use this approach myself, but it can be gotten
around also.

  It's important that you clean these people off your system,
because not only are your own machines at risk, but you may
be held liable for the damage these guys do FROM your systems
to other sites on the internet.




>At my organization, our inept NIS/network adminstrators have blocked
>everyone's workstations in our area from accessing the internet
>through our gateway, except those who have justified getting access,
>authorized by management.
>Unfortunately, the access blocking mechanism they used is pathetically
>easy to get around:
>All our networked (AIX 3.25) systems are on an NIS LAN, with each
>user's account automounted.  They've blocked ftp and telnet by
>authenticating at the originating socket level, meaning that a request
>is authorized if it originates from the authorized system's IP
>address.  All any unauthorized user needs to do is rlogin to my
>system, and initiate the ftp request, and make transfers to globally
>available fileservers.

Since you are using NIS, why don't you make a netgroup of users who are
allowed to log onto the machine, and install that netgroup in the passwd
file on the authorized machine. So in place of the usual NIS map token

instead of              +::0:0:::

Then people not in the group will not be able to log in.  If I have
understood your problem correctly, then this would help (at least until
you find something more elegant).


     We discovered that somebody cracked into our system due to a poor
choice of password by one of our users (password=his first name, ARRGG!!).

I know where this guy logged in from, and he/she even set up an account
for him/herself with /tmp as home directory.

My question is: is there any way to set up a trap? I am far from being
a Unix guru, so any help will be appreciated.

