Re: securityhole /proc/sys/kernel/domainname

Christoph Lameter (clameter@miriam.fuller.edu)
19 Feb 1996 16:07:18 -0800


David Holland (dholland@hcs.harvard.edu) wrote:
: > : PPL who use the nisdomainname as a passwort to protect NIS deserve to
: > : drink warm beer and be slaped with a large trout. Every user on a System
: > : can read the NIS/YP domainname (by getdomainname, sysctl or /proc). Have
: > : u ever typed "nisdomainname" on the prompt?
: >
: > Yes. I have and the users get "permission denied". I want the proc
: > to be fixed and the sysctl too please. Only root access.

: You realize, of course, that this makes NIS completely useless.
Why? The daemons run as root.
I see NIS only as a authentication protocol not as a network information system.