pjohns
20th September 2007, 13:47
I have read quite a few posts on the REXEC and baanlogin protocols and can see that REXEC is not very secure.

We are just moving away from HPUX to RHEL 4 and I'm looking at changing the login method from REXEC to baanlogin. Every year we have a security review done against our systems and REXEC is always noted as a vulnerability. However, before I make this change I would like to know all the pros and cons of using the two Baan login protocols. What do other people generally use?

I would appreciate any comments you may have.

Cheers
PJ

jaotto
28th September 2007, 06:25
Technically there is not really any difference in security except the port number that it uses. It still displays the password as clear text across the network.