[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: rwhod



> Martin Schulze:
> > I believe there are security concerns.  Via rwho protocol your machine
> > distributes information on who is logged in.  So you are able to play
> > big brother and generate personal profiles for instance.
[..]
> 
> Since broadcast packets shouldn't leave your local network, I don't think
> that anyone in the outside world can listen in on the rwho messages, so I
> _think_ it's safe for use if you trust all the hosts on your subnet.

The only reason I have for not running rwho is that one morning,
back in the 1.1.57 days, when I got to the laboritory, my computer was
swiched of, all cables disconected, panic notices were distributed
around the room, and the sysadmin here were spreading panic messages
like fire. Turned out the computer department had a problem with
their system, and related it with my computer -- so the systemadmin
here went compleately crasy.

The only thing I could find in my syslogs before my computer was swiched
off, were a few rwho messages. That's why I'd be weary to start that
service up again, not because I'm on a 100 computer subnetwork: I don't
really care if others see who's logged on here.

(Yeah, I know you're not intereseted in this tragic story about
computer abuse by systemadmins, but I'm still traumatised, and just needed
to vent this).

BTW, the systemadmin that went out of his mind back then has left, so
maybe I can try starting rwho once more?  I'm sure it wasn't rwho
that was causing it, anyway.

-- 
joost witteveen, joostje@debian.org
#!/bin/perl -sp0777i<X+d*lMLa^*lN%0]dsXx++lMlN/dsM0<j]dsj
$/=unpack('H*',$_);$_=`echo 16dio\U$k"SK$/SM$n\EsN0p[lN*1
lK[d2%Sa2/d0$^Ixp"|dc`;s/\W//g;$_=pack('H*',/((..)*)$/)
#what's this? see http://www.dcs.ex.ac.uk/~aba/rsa/


--
TO UNSUBSCRIBE FROM THIS MAILING LIST: e-mail the word "unsubscribe" to
debian-user-request@lists.debian.org . 
Trouble?  e-mail to templin@bucknell.edu .


Reply to: