Subject: Re: rcp or scp
To: David Laight <david@l8s.co.uk>
From: Perry E.Metzger <perry@piermont.com>
List: netbsd-help
Date: 11/22/2003 09:35:43
David Laight <david@l8s.co.uk> writes:
>> FYI, in general, no one should use rcp instead of ssh/scp on the open
>> internet. It is arguable they shouldn't be used behind a firewall,
>> either, if you don't have some pressing reason to use them.
>
> Isn't rcp arguably more secure than ftp?
> To break rcp you need to subvert the reverse DNS.

No, actually, you don't generally attack it that way (and most modern
systems do a forward check, too -- anyone on earth can say their
machine is anything if they run a network segment).

In any case comparing rcp and ftp security is sort of like comparing
the health promoting effects of strychnine and cyanide.

Perry