Re: Re: Encrpted Passwords
droolin <[email protected]>
| Newsgroups | gmane.network.irc.bopm |
|---|---|
| Message-ID | <[email protected]> |
You know, i've thought about this a couple times myself and have to agree with Philipp. I kind of came to the following security procedures to make life more difficult for security purposes: 1). Each shell has a unique passowrd for the bopm. 2). The bopm password found in the unreal conf for oper purposes is cyrpted. 3). The bopm only requires an global oline, they should not be able to cause much damage. 4). A csop/netadmin has the ability to remove oline status online if a security break occurs.(svsmode I think) Worse case, jupe the server. Id do that anyway, just because it was a security leak/problem. At least till the security issue was resolved. I look at it this way, if the bopm oper password is compromised. It is most likely due to a person has had access to the shell, and was able to acquire this information. If a person has access to a shell, they can create their own oline. So, crypting the bopm password really dont accomplish anything. Again, another reason to just jupe the server. droolin > > From: Philipp Kern <[email protected]> > Date: 2003/11/07 Fri AM 11:04:09 EST > To: Wayne <[email protected]> > CC: [email protected] > Subject: Re: [bopm] Encrpted Passwords > > On Fri, 2003-11-07 at 16:27, Wayne wrote: > > The reason i ask is my network suffered a security leak somewhere and > > a bopm password was discovered and used to oper up on my network. If > > i am able to encrypt the password like i do with unreal it would help > > me greatly. > > You need to fix the leak. > Think. If the password is encrypted, how would bopm be able to decrypt > it? > Unreal only needs to check if the password supplied is encrypted the > same as the saved. > > Bye, > phil > -- > Philipp Kern <[email protected]> > Homepage: http://www.philkern.de - ICQ#: 66737654 > >