HP3000-L Archives

March 2001, Week 4

HP3000-L@RAVEN.UTC.EDU

Options: Use Monospaced Font
Show Text Part by Default
Show All Mail Headers

Message: [<< First] [< Prev] [Next >] [Last >>]
Topic: [<< First] [< Prev] [Next >] [Last >>]
Author: [<< First] [< Prev] [Next >] [Last >>]

Print Reply
Subject:
From:
Reply To:
Date:
Thu, 22 Mar 2001 14:46:44 -0500
Content-Type:
text/plain
Parts/Attachments:
text/plain (36 lines)
> Hi HP3000-L,

> Thank you to the people who replied privately to me and said to have the
PC
> reference the shares as \\ipaddress\sharename.

> Mark Bixby wrote:
>> I'm trying to configure Samba/iX 2.0.7 on MPE 6.5 for the first time.
The
So, at this point, you're talking to yourself in public.

> Are there any other things I should be doing to protect Samba from the big
bad
> Internet?  There may be a few public/guest read-only shares.  All users of
the
> machine will be able to attach to their [homes] shares if they know a
valid
> USER.ACCOUNT and UPASS,APASS.
Well, I don't think Samba has a "three strikes, you're out" rule, so the
script kiddies can bang away all day trying to find good username & password
combos. I guess that makes a good point of security auditing. Since the
absence of the lockout betrays that the machine is more likely Samba than
MS, I have to wonder about the more common username and password combos as
likely targets, although those are less of an issue for MPE / Samba/iX.
Read-only seems safe enough, although useful information there can become
useful to the script kiddies, even your email address (maybe a throwaway
would be a good idea?). I don't know the likelihood of them figuring out
anything from the home shares, but I would go ahead and set limits on their
sizes, and I guess make that another audit point.

I look forward to seeing what comes of this, and if I can help test, just
ask. All the best.

Greg Stigers
http://www.cgiusa.com

ATOM RSS1 RSS2