samba ver 2 beta 1 (gaping wide bug)

Juan Carlos Castro y Castro jcastro at pcshop.com.br
Mon Nov 16 21:58:08 GMT 1998


Geez! This is a MAJOR Windows security bug! Security at the server shouldn't depend
on clients being "nice". This is what happens when a protocol is treated as
proprietary.

Mark Deneen wrote:

> Please excuse me if this has been covered, but I just noticed something odd
> with samba 2 beta 1.  If I use smbclient to connect to a passworded resource on
> a win machine (I've tried it with 98/95) and I just hit enter for the password,
> it lets me in.  No questions asked.  So, I pretty much have unlimited read
> access to stuff I should not be able to get to.
>
> Best Regards.
>
> If this is the wrong list to send this to, please direct me in the right path.
> ---
> Mark Deneen
> deneen at bucknell.edu ICQ: 333068
> http://www.students.bucknell.edu/deneen
>
> revolutionary, adj.:
>         Repackaged.



--

**************************************
*   Depois de tudo que aconteceu,    *
*           você AINDA vai           *
*  botar dinheiro na mão da NIKE??   *  OGY IS POLICY @ THE END
**************************************  L     *****************
                                        O     *     FIGHT     *
UST NO ONE @ DE  E @ BELIEVE THE LIE @ AP     *      THE      *
R             N  T                            *   FUTURE!!!   *
T  ___THE___  Y  A                            *****************
   \  \ /  /     CSUFBO @ EVRES RO TSISER @ ELGIEVNI @ EVIECED @ ET E @
    \  V  /   E  _______________________________________________  O L
     \   /    V |Juan Carlos Castro y Castro                    | H   S
     /   \    E |jcastro at pcshop.com.br                          |   A E
    /  ^  \   R |Linuxeiro, alvinegro, X-Phile e Carioca Folgado| O A I
   /  / \  \  Y |Diretor de Informática e Eventos Sobrenaturais | GIN D
   ~~~   ~~~  T |da E-RACE CORPORATION                          |
     RACER    H  -----------------------------------------------      G
              ING @ E PUR SI MUOVE @ THE TRUTH IS OUT THERE @ EVERYTHIN




More information about the samba mailing list