HP3000-L Archives

March 2000, Week 3

HP3000-L@RAVEN.UTC.EDU

Options: Use Monospaced Font
Show Text Part by Default
Show All Mail Headers

Message: [<< First] [< Prev] [Next >] [Last >>]
Topic: [<< First] [< Prev] [Next >] [Last >>]
Author: [<< First] [< Prev] [Next >] [Last >>]

Print Reply
Subject:
From:
"Stigers, Greg [And]" <[log in to unmask]>
Reply To:
Stigers, Greg [And]
Date:
Wed, 15 Mar 2000 12:31:53 -0500
Content-Type:
text/plain
Parts/Attachments:
text/plain (41 lines)
X-no-Archive:yes
Apparently, 55 prevents ftp from signing on to a BA only user, and 60 allows
it. Independent confirmation of this would be welcome, as would an
explanation. The reason for this may (or may not) be hinted at in James
Hofmeister's post earlier today, FTP Server Messages, where he writes:

I won't belabor the point that with FTP under INETD on 6.0 and
beyond that a logon does not take place.  With FTP on 6.0, a socket
connection is established and then a AIFCHANGELOGON is executed to
establish the correct file system / directory / security attributes
for the data to be copied to/from the system.

-----Original Message-----
From: Costas Anastassiades [mailto:[log in to unmask]]
Sent: Wednesday, March 15, 2000 3:14 AM
To: [log in to unmask]
Subject: Re: Creating an "FTP only" user

<snip>
Log on is
unsuccessful when the user only has BA. I'm guessing that a particular
version of FTP/MPE doesn't require IA. Could you tell me what MPE version
you are on ?
<snip>
-----Original Message-----
From: HP-3000 Systems Discussion [mailto:[log in to unmask]]On
Behalf Of Ken Kirby
Sent: Friday, March 10, 2000 5:34 PM
To: [log in to unmask]
Subject: Re: Creating an "FTP only" user

<snip>
Personally, I think this is a security hole, since it allows someone to
logon to a "BA only" account using an interactive tool. However, in this
case, it could work to your advantage.

--Ken Kirby
  Management Information Systems
  Vanderbilt University
<snip>

ATOM RSS1 RSS2