Xref: utzoo news.sysadmin:1955 news.admin:4320 Path: utzoo!attcan!uunet!ncrlnk!ncrcae!ece-csc!mcnc!xanth!ames!mailrus!tut.cis.ohio-state.edu!triceratops.cis.ohio-state.edu!karl From: karl@triceratops.cis.ohio-state.edu (Karl Kleinpaste) Newsgroups: news.sysadmin,news.admin Subject: Re: rnews: security hole. Too bad. Message-ID: Date: 16 Dec 88 20:37:16 GMT References: <1219@altger.UUCP> <2567@stpstn.UUCP> <1299@vsi1.COM> Sender: news@tut.cis.ohio-state.edu Organization: OSU Lines: 13 In-reply-to: lmb@vicom.COM's message of 15 Dec 88 18:13:01 GMT lmb@vicom.COM (Larry Blair) writes: Not true. You can dump news on any system that you have a uucp connection to. I could dump all of our news on, say, osu-cis, if I wanted to. About the only way they could stop me would be to remove "rnews" from the L.cmds file (or remove the anonymous login). Joe Buck's response had it on the ball here. osu-cis runs HDB UUCP, and the Permissions file entry for the Uanon login allows rmail (people having trouble with archive access tend to like to write us mail about what's wrong) but not rnews. Real news neighbors don't use Uanon. I suspect that most archive sites have similar arrangements. --Karl