[OpenAFS] token theft under XP
Rodney M Dyer
rmdyer@uncc.edu
Thu, 12 Dec 2002 15:46:44 -0500
At 01:29 PM 12/12/2002 -0600, Charles Clancy wrote:
> > >Scenario:
> > >1. domain user 'x' logs in, gets tokens
> > >2. 'x' logs out
> > >3. local machine administrator goes in and creates local user 'x'
> > >4. log in as local user 'x'
> > >5. local user has access to the token and drive mappings obtained by the
> > > domain user
> >
> > Umm, have you tried this?
>
>Yes. Otherwise I wouldn't have posted it (or noticed it for that matter).
Btw, we use Transarc's AFS 3.6 patch 4 (v2.32) and I've never seen this
problem.
Rodney
>I used the 1.2.6 client under WinXP.
>
>I understand that PAGs would solve the problem, but the little systray
>icon tokens tool doesn't do that by default.
>
>[ t charles clancy ]--[ tclancy@uiuc.edu ]--[ www.uiuc.edu/~tclancy ]
>
>_______________________________________________
>OpenAFS-info mailing list
>OpenAFS-info@openafs.org
>https://lists.openafs.org/mailman/listinfo/openafs-info