Ethical Hacking

Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package.
Computer Forensics Training at InfoSec Institute

Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors.




Network Security Security-Basics
[Top] [All Lists]

Need help on .rhosts vs hosts.eqiv

Subject: Need help on .rhosts vs hosts.eqiv
Date: Thu, 20 Jan 2005 15:03:52 -0800 (PST)
Hi,

Does anyone know the proper issues techniques or have
good documentation/info relating to .rhosts and
hosts.equiv.  I have been googling information on it
but I haven't been able to get a concrete solid
information on these things.  

For example:  There are 3 systems A,B, and C.  Lets
just focus on hosts.equiv.  

System A and B both have themselves defined in their
hosts.equiv.  And a user John exists on both the
systems (in /etc/passwd..working account).  So John
should be able to go into A and B as himself without
typing the password as he jumps from A to B.  

And in System A there is a user called Jane.  She does
not have an account in System B.  Now can she jump to
system B? as herself or other user?  I assume she
won't be able to jump to system B am I correct? And
will the system ask for her password...even though she
does not have an account ?

For System C.  John exists in this system also, but
this system does not exist in hosts.equiv of System A
or B.  Would John be able to jump from C to A or B?  I
assume he can't ... am I right on this one?

For .rhosts

On System B - John has a .rhosts file and he allows a
user called Tom to access his home directory.  But
user Tom does not exist on System B, he only exists on
system A.  Will this scenario work or will System B
ask Tom for his password? or would it just allow it.


Any help with good info on proper workings of .rhosts
and hosts.equiv would be greatly appreciated.  


I have really searched google on this.  I got some
leads, but I would like to ask all you security gurus
on this.  I am really baffled at this.  And I
currently do not have a system(s) to try this.  

Any help is greatly appreciated.

Thanks,

nuero

<Prev in Thread] Current Thread [Next in Thread>
  • Need help on .rhosts vs hosts.eqiv, Nuerostar <=