Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I worked at an ISP that ran a couple of its web servers on Indy's. The hardware was nice, but IRIX 5.x was kind of a mess. It came out of the box with very loose security. X11 was open to the world (equivalent of "xhost +".) This meant anyone could key log you from remote if you were logged into the console.


Those days were a magical time for a teenager poking around. A lot of things were directly connected to the β€˜net without a firewall or behind a NAT gateway. I wish I had the knowledge I have today back then.


I remember vividly. A friend literally "owned" a few local universities that had lax security, then gave out credentials to a bunch of other teens on some underground BBSes. They were hogging all the modem pools, compiling their own IRC clients on the university Sun boxes, and causing general mayhem. This went on for a while until they finally locked things down. The late 80's, early 90's were crazy times.


We had a build of ipfilter at the time installed, as we were aware of that. Even got OpenLDAP compiling for IRIX 5.3 and migrated all the local accounts into that, before building an UltraSparc 10 compatible server from parts from Sun Microelectronics and moving the LDAP server function to there. Those were the days.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: