[Search for users] [Overall Top Noters] [List of all Conferences] [Download this site]

Conference noted::decnis

Title: DEC Network Integration Server (DECNIS)
Notice:Please read note 1 to use this conference effectively
Moderator:MARVIN::WELCH
Created:Wed Sep 18 1991
Last Modified:Thu Jun 05 1997
Last Successful Update:Fri Jun 06 1997
Number of topics:3660
Total number of notes:15082

3637.0. "override DECNIS access password" by TAV02::SHUKY () Wed May 14 1997 05:51

  At past, a DECNIS 500 was configured and loaded by a PC .
  Now , at customer site, the PC has gone, and their is no load host for it.
 
  How can I get all the security info from the DECNIS without knowing the 
  access password, in order to redefine the DECNIS in a new load host.

  Shuky.
T.RTitleUserPersonal
Name
DateLines
3637.1No break in for DECNIS securityMARVIN::RIGBYNo such thing as an alpha betaWed May 14 1997 11:0512
You can't over the network, and if you could it would be a security hole.

If you have an MPC-II (or -III) and have access to NCL from the console you
could get the information there. If you use TELNET to get to said console you
would need to supply the TELNET password, which you probably don't know either.

For large sums of money you could supply a dump, the information is in memory
and could, conceptually, be extracted from there as it isn't stored with one-way
encryption but we have no tools to help in this job and I'm sure it would be
much cheaper to just create the security information from scratch.

John
3637.2More money, but quicker !COMICS::WEIRJohn Weir, UK Country SupportWed May 14 1997 16:4037
For even larger sums of money I'll tell you how to do it in about 30 seconds ;-)

Regards,

	John Weir























Oh! BTW, all you have to do is get your DECnis dump to a VMS system and do

	$ SEARCH nis_fred.dmp OBJ_19,LES$CTF

There are several occurences of both OBJ_19 and LES$CTF, and shortly after
one or other of the occurences (last occurences in my dump) you will find the
usernames and passwords in clear text -- Obviously the NML one is shortly
after the OBJ_19 string and the CTF one is after the LES$CTF string.
3637.3Protect those dumpsMARVIN::RIGBYNo such thing as an alpha betaThu May 15 1997 09:275
oh well, that blows it, we'll have to withdraw all versions of DECNIS code while
we fix this security hole.-)

This possibility once again emphasizes how important it is to make sure that any
DECNIS dumps you have lying around on your system are suitably protected.