[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

[suse-security] Re: passwd on website



On Mon, 6 Oct 2003, [ISO-8859-1] Dominik Sk?adanowski wrote:

>  [...]
>  >>I need to have change system password through website.
>  >
>  >
>  > erks!
>  > but if you realy need it, ...
>
> Unfortunatelly I have to make this... Access will be limited to intranet.

There is nothing like a free meal. There is also nothing like "Unfor-
tunatelly I have to make this"!

This _will_ heavily weaken the security of your system. Make shure that
it is not you who is responsible for this security flaw and also that it
is not you who has to do the work if somebody broke in via this
"feature".

Regards
    Henning Hucke
-- 
An expert is a person who avoids the small errors
as he sweeps on to the grand fallacy.
		-- Benjamin Stolberg

-- 
Check the headers for your unsubscription address
For additional commands, e-mail: suse-security-help@xxxxxxxx
Security-related bug reports go to security@xxxxxxx, not here