Executive brief
The Network Information Service (NIS), a system used to manage and share configuration data across a network, uses domain names that are easily guessed. If an attacker identifies the domain name, they can gain unauthorized access to sensitive system information, including password files and administrative data. This could lead to a complete compromise of the affected systems and the data they manage.
Technical details
The vulnerability stems from the use of weak or predictable NIS domain names (often matching the DNS domain or hostnames). NIS relies on the domain name as a primary authentication token; if an attacker knows or guesses the domain name, they can use NIS client tools to request sensitive maps such as 'passwd.byname' or 'hosts' from the NIS server. This is a local attack vector in the sense that the attacker typically needs to be on a network that can reach the NIS server, but it results in a complete loss of confidentiality, integrity, and availability. Mitigation involves using non-obvious domain names and implementing secure RPC or transitioning to more secure directory services like LDAP.
Affected products
- Sun Microsystems Network Information Service (NIS)
Timeline
- 1992-12-31: advisory: CERT advisory CA-1992-13 published
- 1997-01-01: disclosed: NVD publication date