[mod.computers.vax] Defeating the secondary password

AWalker@RED.RUTGERS.EDU.UUCP (01/27/87)

There are two instances I can think of that allow an account with two passwords
to "log in" using only one.

The "authorization" window on a Vaxstation [vs100, not microvax workstation]
accepts one password, the first one, and will then create jobs with that
username from then on whether that account had a second password or not.

The Wollongong FTP server, and I suspect others, will "log in" an incoming
connection when just the first password is supplied.

So much for paranoid security!

_H*
-------