ADSM-L

How things work....

1995-04-28 16:31:37
Subject: How things work....
From: Jerry Lawson <jlawson AT ITTHARTFORD DOT COM>
Date: Fri, 28 Apr 1995 15:31:37 EST
>
>   Your scenario number 3 for spoofing a client won't work.
>The server and client have mutual authentication.  You can't
>spoof a client by pretending to be a server unless you
>already know both the password and the authentication algorithm.

Barry - It's good to here that it isn't that easy - I should have thought of
the password issue.  :-( But then again, I don't go around trying to figure
out how to beat security systems, either.  We have discussed how someone could
get into the database on the server, and at least on MVS, came to the
conclusion that you would have to be pretty good to figure out what was there,
between the compression and the ASCII/EBCIDIC conversion.  There was also a
question about whether we could get an MVS virus from a PC, and we thought
that while perhaps possible, the hacker would have to be real good to develop
a virus that would work when it was compressed and transferred from one
environmrnt to another.

Jerry
<Prev in Thread] Current Thread [Next in Thread>
  • How things work...., Jerry Lawson <=