× The internal search function is temporarily non-functional. The current search engine is no longer viable and we are researching alternatives.
As a stop gap measure, we are using Google's custom search engine service.
If you know of an easy to use, open source, search engine ... please contact support@midrange.com.



Hi Kevin, Greg,

You could also write your own validation program for the CHGPWD command.

hth,
Peter Dow
Dow Software Services, Inc.
909 425-0194 voice
909 425-0196 fax

----- Original Message -----
From: "Greg Day" <greg_day@hotmail.com>
To: <midrange-l@midrange.com>
Sent: Monday, February 25, 2002 7:41 PM
Subject: RE: BugTraq Exploit for OS/400


> >From: Kevin_a_Layne@CRCMN.COM
> >A system value that does not allow default passwords
> >would be a good idea and is not there as of 4r4.
> >Kevin Layne
>
> Kevin, You could write your own Create User Profile program and Enable
User
> Profile program to ensure default passwords are not used. Then use
ANZDFTPWD
> to monitor. Schedule it to run nightly.
>
> I have seen many profiles get created with default passwords and the user
> never gets around to using the signon, or there's a delay of some weeks
> before they use it. This is a vulnerability, especially if the User Id
> naming format is easily guessed, which I suggest it would be for an
insider.
>
> Forget the outside hacker, what percentage of security incidents occur
from
> disgruntled staff? I don't know, but it is high.
> Greg
>
> _________________________________________________________________
> Send and receive Hotmail on your mobile device: http://mobile.msn.com
>
> _______________________________________________
> This is the Midrange Systems Technical Discussion (MIDRANGE-L) mailing
list
> To post a message email: MIDRANGE-L@midrange.com
> To subscribe, unsubscribe, or change list options,
> visit: http://lists.midrange.com/cgi-bin/listinfo/midrange-l
> or email: MIDRANGE-L-request@midrange.com
> Before posting, please take a moment to review the archives
> at http://archive.midrange.com/midrange-l.


_________________________________________________________
Do You Yahoo!?
Get your free @yahoo.com address at http://mail.yahoo.com



As an Amazon Associate we earn from qualifying purchases.

This thread ...

Replies:

Follow On AppleNews
Return to Archive home page | Return to MIDRANGE.COM home page

This mailing list archive is Copyright 1997-2024 by midrange.com and David Gibbs as a compilation work. Use of the archive is restricted to research of a business or technical nature. Any other uses are prohibited. Full details are available on our policy page. If you have questions about this, please contact [javascript protected email address].

Operating expenses for this site are earned using the Amazon Associate program and Google Adsense.