Re: securityhole /proc/sys/kernel/domainname

Christoph Lameter (clameter@miriam.fuller.edu)
19 Feb 1996 03:46:11 -0800


Bernd Eckenfels (ukd1@rzstud1.rz.uni-karlsruhe.de) wrote:
: Christoph Lameter (clameter@miriam.fuller.edu) wrote:
: > this file should not be world readable. As I understand the Yellow Pages the
: > domainname is a kind of password that allows NIS access.

: PPL who use the nisdomainname as a passwort to protect NIS deserve to drink
: warm beer and be slaped with a large trout. Every user on a System can read
: the NIS/YP domainname (by getdomainname, sysctl or /proc). Have u ever typed
: "nisdomainname" on the prompt?

Yes. I have and the users get "permission denied". I want the proc to be fixed and
the sysctl too please. Only root access.