From owner-freebsd-security Thu Oct 26 03:55:55 1995 Return-Path: owner-security Received: (from root@localhost) by freefall.freebsd.org (8.6.12/8.6.6) id DAA01356 for security-outgoing; Thu, 26 Oct 1995 03:55:55 -0700 Received: from tfs.com (tfs.com [140.145.250.1]) by freefall.freebsd.org (8.6.12/8.6.6) with SMTP id DAA01349 for ; Thu, 26 Oct 1995 03:55:49 -0700 Received: from critter.tfs.com by tfs.com (smail3.1.28.1) with SMTP id m0t8PyD-0003wsC; Thu, 26 Oct 95 03:55 PDT Received: from localhost (localhost [127.0.0.1]) by critter.tfs.com (8.6.11/8.6.9) with SMTP id LAA01040; Thu, 26 Oct 1995 11:55:34 +0100 X-Authentication-Warning: critter.tfs.com: Host localhost didn't use HELO protocol To: gwk@cray.com cc: davidg@Root.COM, dab@berserkly.cray.com, hartmans@mit.edu, security@freebsd.org Subject: Re: telnetd fix In-reply-to: Your message of "Thu, 26 Oct 1995 11:40:08 +0100." <199510261040.LAA16603@racer.dkrz.de> Date: Thu, 26 Oct 1995 11:55:34 +0100 Message-ID: <1038.814704934@critter.tfs.com> From: Poul-Henning Kamp Sender: owner-security@freebsd.org Precedence: bulk > > X-Authentication-Warning: critter.tfs.com: Host localhost didn't use HELO p rotocol > > cc: dab@berserkly.cray.com (David A. Borman), hartmans@mit.edu, > > security@freebsd.org > > Date: Wed, 25 Oct 1995 10:03:07 +0100 > > From: Poul-Henning Kamp > > Sender: owner-security@freebsd.org > > Precedence: bulk > > > > > At the moment, I'm seriously considering adding a switch to shut off t he > > > feature in FreeBSD's telnetd and making it the default in inetd.conf. > > > > YES! > > > > -- > > Poul-Henning Kamp | phk@FreeBSD.ORG FreeBSD Core-team. > > NO! > > I'd rather like to see a statically linked login, which would plug the > hole without any side-effects. Well, we rely on login being able to find one of two different libcrypt to handle the DES versus MD5 encryption... So, nice idea, bad idea... -- Poul-Henning Kamp | phk@FreeBSD.ORG FreeBSD Core-team. http://www.freebsd.org/~phk | phk@login.dknet.dk Private mailbox. whois: [PHK] | phk@ref.tfs.com TRW Financial Systems, Inc. Future will arrive by its own means, progress not so.