Ascend Archive
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: (ASCEND) security hole in p50



This is only if you don't change the access in the security profile, its
relatively simple to turn off if you pay attention to what your doing. I
agree that its silly to have that as the default but... its ascend :)

On Wed, Dec 10, 1997 at 01:22:11PM +1100, Skeeve Stevens made some electrons appear in the following form:
> 
> 
> In the p50 running +5.1A+ ive discovered a security hole while fiddling around
> last week.
> 
> The 3 levels of access are pointless because once you have the telnet password,
> it allows you to go into diagnostic mode and dump the p50's config to a 
> tftp server, complete with all passwords for the unit....
> 
> Silly silly ascend.
> 
>      ---------------------------------------------------------------------
>     | Skeeve Stevens - myinternet    personal.url: http://www.skeeve.net/ |
>     | email://skeeve@skeeve.net/     work.url: http://www.myinternet.net/ |
>     | phone://612.9876.4527/         mobile://0414.SKEEVE/      [753-383] |
>     |              No kids, no chat room, no smiley faces.                |
>     | - This email is (c) 1997 by Skeeve Stevens - All rights reserved -  |
>      ---------------------------------------------------------------------
> ++ Ascend Users Mailing List ++
> To unsubscribe:	send unsubscribe to ascend-users-request@bungi.com
> To get FAQ'd:	<http://www.nealis.net/ascend/faq>

-- 
++ Ascend Users Mailing List ++
To unsubscribe:	send unsubscribe to ascend-users-request@bungi.com
To get FAQ'd:	<http://www.nealis.net/ascend/faq>


Follow-Ups: References: