<<On Fri, 18 Feb 2000 09:43:03 +0200, Mark Murray <[EMAIL PROTECTED]> said:

> o A username may only be checked $number times per $timeperiod;
>   after that, _all_ answers are silently converted to "no".

Easier: a username may only be checked by a process running as $uid
or by root.

> ... etc. There are possibilities for DoS attacks, but the daemon
> talks only to a Unix Domain Socket, so finding the perp is easy.

And what happens when the daemon is dead, has crashed, or was never
started?

-GAWollman

--
Garrett A. Wollman   | O Siem / We are all family / O Siem / We're all the same
[EMAIL PROTECTED]  | O Siem / The fires of freedom 
Opinions not those of| Dance in the burning flame
MIT, LCS, CRS, or NSA|                     - Susan Aglukark and Chad Irschick


To Unsubscribe: send mail to [EMAIL PROTECTED]
with "unsubscribe freebsd-current" in the body of the message

Reply via email to