Re: guest account - security

From: Johnn D. Tan (jdtan@MED.CORNELL.EDU)
Date: Thu Sep 26 2002 - 17:31:34 EDT


No, that's not true. They are created by default install of AIX 4.3.3
guest:!:100:100::/home/guest:

As part of our default AIX setup scripts, we remove the guest account.

As for anonymous, AIX 4.3.3, to my knowledge, doesn't have a default
anonymous account, so unless you're running WU-FTP or some other FTP
server, there's no such account to be able to login with anyway.

johnn

>Under normal circumstances, these accounts do not exist. I believe that if
>you see them, they were created by someone. But I could be wrong.
>
>BV
>--------------------------------------------------------------------------------------------------------
>
>Bill Verzal
>Technical Consultant
>Forbes Technical Consulting
>(312) 653-3684
>bill_verzal@bcbsil.com
>MailStop: 27.202B
>
>
>
> "Tim Brumfield"
> <tbrumfield@MMRS.ST To: aix-l@Princeton.EDU
> ATE.MS.US> cc:
> Sent by: "IBM AIX Subject: guest
>account - security
> Discussion List"
> <aix-l@Princeton.ED
> U>
>
>
> 09/26/2002 03:51 PM
> Please respond to
> "IBM AIX Discussion
> List"
>
>
>
>
>
>
>Good day list. I have a general question relating to security. I am
>trying to secure 2 servers, one running AIX 5.1 and an SP running AIX
>4.3. I am considering how so secure the guest account.. Do most
>administrators lock it down or remove it? Also, on ftps, do most admins
>lock down the "anonymou" account, or remove it? I am thinking that I
>will simply remove it since I don't anticipate anonymous ftps but would
>like some feedback from persons more experienced.
>Any comments or suggestions would be helpful. Thanks to all.
>
>-Tim



This archive was generated by hypermail 2.1.7 : Wed Apr 09 2008 - 22:16:13 EDT