> <<On Fri, 18 Feb 2000 09:43:03 +0200, Mark Murray <[EMAIL PROTECTED]> said:
> 
> > o A username may only be checked $number times per $timeperiod;
> >   after that, _all_ answers are silently converted to "no".
> 
> Easier: a username may only be checked by a process running as $uid
> or by root.

... added to the list of possibles.

> > ... etc. There are possibilities for DoS attacks, but the daemon
> > talks only to a Unix Domain Socket, so finding the perp is easy.
> 
> And what happens when the daemon is dead, has crashed, or was never
> started?

Answer is "no". Possible DoS attack to be addressed.

M
--
Mark Murray
Join the anti-SPAM movement: http://www.cauce.org


To Unsubscribe: send mail to [EMAIL PROTECTED]
with "unsubscribe freebsd-current" in the body of the message

Reply via email to