Displaying 3 results from an estimated 3 matches for "michief".
Did you mean:
michiel
2004 Aug 06
2
a new directory service
...her.
Yes it is. To spoof the address you'd have to guess the password.
That is reasonable difficult.
> Someone can sniff the
> hash and then they don't have to spoof,
Sniffing is quite difficult. If you can sniff, you've likely gotten
onto the box anyway and can cause other michief. The chances of someone
on your network wanting to muck with you is slim, and even so, challenge
response prevents this.
You can still sniff the transmission to the directory server, since it
will need to receive the password. But like I said, this isn't perfect,
just quite adequate for our...
2004 Aug 06
0
a new directory service
...ea of listener counts that I was
thinking that you weren't going to have support for them in any way, shape
or form in this new project.. that's why I mentioned it. ;)
>Sniffing is quite difficult. If you can sniff, you've likely gotten
>onto the box anyway and can cause other michief. The chances of someone
>on your network wanting to muck with you is slim, and even so, challenge
>response prevents this.
Well to sniff they just have to compromise any box on the network, not just
one. Even if it's switched, they can blow through the switch with bogus
ARP storms.....
2004 Aug 06
2
a new directory service
I apologize for the delay in response time :)
I got busy. Now I'm back :)
> >Go read a basic document on Internet Standards. Encoding meta
> >information (especially type) in a filename or URL is broken and wrong.
>
> I wasn't suggesting it be encoded in the URL.. only that if you go to the
> URL (not the client-listen url, the website url) there should state