<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Prevent passwd file from being copy in Operating System - HP-UX</title>
    <link>https://community.hpe.com/t5/operating-system-hp-ux/prevent-passwd-file-from-being-copy/m-p/2456851#M12773</link>
    <description>Hi,&lt;BR /&gt;&lt;BR /&gt;to have full information about ftp sessions edit the /etc/inetd.conf:&lt;BR /&gt;Change the line:&lt;BR /&gt;ftp  stream tcp nowait root /usr/lbin/ftpd ftpd -l&lt;BR /&gt;TO:&lt;BR /&gt;ftp  stream tcp nowait root /usr/lbin/ftpd ftpd -l -v&lt;BR /&gt;Now reinitialize inetd with: inetd -c&lt;BR /&gt;After this you get all ftp commands and files logged in /var/adm/syslog/syslog.log&lt;BR /&gt;&lt;BR /&gt;Regards</description>
    <pubDate>Tue, 24 Oct 2000 05:47:09 GMT</pubDate>
    <dc:creator>Andreas Voss</dc:creator>
    <dc:date>2000-10-24T05:47:09Z</dc:date>
    <item>
      <title>Prevent passwd file from being copy</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/prevent-passwd-file-from-being-copy/m-p/2456848#M12770</link>
      <description>Hi,&lt;BR /&gt;&lt;BR /&gt;Is there a way to prevent the password file being copied or ftp ? &lt;BR /&gt;&lt;BR /&gt;If not possible, is there a way to trap who has ftp or copied this file and get notify ?&lt;BR /&gt;&lt;BR /&gt;Any advise is apprecaited.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Rgds,&lt;BR /&gt;YC</description>
      <pubDate>Tue, 24 Oct 2000 01:00:37 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/prevent-passwd-file-from-being-copy/m-p/2456848#M12770</guid>
      <dc:creator>yc_2</dc:creator>
      <dc:date>2000-10-24T01:00:37Z</dc:date>
    </item>
    <item>
      <title>Re: Prevent passwd file from being copy</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/prevent-passwd-file-from-being-copy/m-p/2456849#M12771</link>
      <description>Hi,&lt;BR /&gt;You could use tsconvert to convert the system to a trusted system and the passwords are moved to a TCB area.&lt;BR /&gt;This will also enable other features as password lifetime etc.&lt;BR /&gt;</description>
      <pubDate>Tue, 24 Oct 2000 01:08:46 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/prevent-passwd-file-from-being-copy/m-p/2456849#M12771</guid>
      <dc:creator>Vinit Adya</dc:creator>
      <dc:date>2000-10-24T01:08:46Z</dc:date>
    </item>
    <item>
      <title>Re: Prevent passwd file from being copy</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/prevent-passwd-file-from-being-copy/m-p/2456850#M12772</link>
      <description>Leong: &lt;BR /&gt;I completely agree with Adya. You need to make the system a Trusted System to prevent users to read the /etc/passwd file. Once the System is converted to a trusted system a protected password database at /tcb/files/auth gets created and a  a "*" &lt;BR /&gt;replaces the password field in /etc/passwd.&lt;BR /&gt;For a detailed information on adminstering trusted system, here is the URL.&lt;BR /&gt;&lt;BR /&gt;&lt;A href="http://docs.hp.com/cgi-bin/onlinedocs.py?mpn=B2355-90121&amp;amp;service=hpux&amp;amp;path=../B2355-90121/00/00/1&amp;amp;title=Administering%20Your%20HP-UX%20Trusted%20System" target="_blank"&gt;http://docs.hp.com/cgi-bin/onlinedocs.py?mpn=B2355-90121&amp;amp;service=hpux&amp;amp;path=../B2355-90121/00/00/1&amp;amp;title=Administering%20Your%20HP-UX%20Trusted%20System&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;Enjoy !&lt;BR /&gt;......Madhu</description>
      <pubDate>Tue, 24 Oct 2000 04:11:31 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/prevent-passwd-file-from-being-copy/m-p/2456850#M12772</guid>
      <dc:creator>Madhu Sudhan_1</dc:creator>
      <dc:date>2000-10-24T04:11:31Z</dc:date>
    </item>
    <item>
      <title>Re: Prevent passwd file from being copy</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/prevent-passwd-file-from-being-copy/m-p/2456851#M12773</link>
      <description>Hi,&lt;BR /&gt;&lt;BR /&gt;to have full information about ftp sessions edit the /etc/inetd.conf:&lt;BR /&gt;Change the line:&lt;BR /&gt;ftp  stream tcp nowait root /usr/lbin/ftpd ftpd -l&lt;BR /&gt;TO:&lt;BR /&gt;ftp  stream tcp nowait root /usr/lbin/ftpd ftpd -l -v&lt;BR /&gt;Now reinitialize inetd with: inetd -c&lt;BR /&gt;After this you get all ftp commands and files logged in /var/adm/syslog/syslog.log&lt;BR /&gt;&lt;BR /&gt;Regards</description>
      <pubDate>Tue, 24 Oct 2000 05:47:09 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/prevent-passwd-file-from-being-copy/m-p/2456851#M12773</guid>
      <dc:creator>Andreas Voss</dc:creator>
      <dc:date>2000-10-24T05:47:09Z</dc:date>
    </item>
    <item>
      <title>Re: Prevent passwd file from being copy</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/prevent-passwd-file-from-being-copy/m-p/2456852#M12774</link>
      <description>Hi Andreas,&lt;BR /&gt;&lt;BR /&gt;Thanks for your advise. &lt;BR /&gt;&lt;BR /&gt;Is there a way to know what files being down loaded because the syslog.log only capture the ftp login name but not the name of the files that being down loaded.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Rgds,&lt;BR /&gt;YC</description>
      <pubDate>Tue, 24 Oct 2000 07:20:57 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/prevent-passwd-file-from-being-copy/m-p/2456852#M12774</guid>
      <dc:creator>yc_2</dc:creator>
      <dc:date>2000-10-24T07:20:57Z</dc:date>
    </item>
    <item>
      <title>Re: Prevent passwd file from being copy</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/prevent-passwd-file-from-being-copy/m-p/2456853#M12775</link>
      <description>Hi,&lt;BR /&gt;&lt;BR /&gt;if you have added the -v option in /etc/inetd.conf at ftp line and reinitialized inetd with inetd -c you get a complete list what a user has done in a ftp session, looks like:&lt;BR /&gt;Oct 24 09:28:33 hpk2202 ftpd[7175]: connection from PC203 at Tue Oct 24 09:28:33 2000&lt;BR /&gt;Oct 24 09:28:33 hpk2202 ftpd[7175]: FTP LOGIN FROM PC203, voss&lt;BR /&gt;Oct 24 09:28:33 hpk2202 ftpd[7175]: FTP: cwd /baan/FT/RETRIEVAL&lt;BR /&gt;Oct 24 09:28:33 hpk2202 ftpd[7175]: PORT&lt;BR /&gt;Oct 24 09:28:33 hpk2202 ftpd[7175]: FTP: retrieve ftp.out&lt;BR /&gt;Oct 24 09:28:34 hpk2202 ftpd[7175]: FTP: delete ftp.out&lt;BR /&gt;Oct 24 09:28:34 hpk2202 ftpd[7175]: User voss  logged out&lt;BR /&gt;&lt;BR /&gt;As you can see the user changed to dir /baan/FT/RETRIEVAL (cwd), copied the file ftp.out (retrieve) and finally removed that file (delete).&lt;BR /&gt;&lt;BR /&gt;Regards</description>
      <pubDate>Tue, 24 Oct 2000 07:34:01 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/prevent-passwd-file-from-being-copy/m-p/2456853#M12775</guid>
      <dc:creator>Andreas Voss</dc:creator>
      <dc:date>2000-10-24T07:34:01Z</dc:date>
    </item>
    <item>
      <title>Re: Prevent passwd file from being copy</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/prevent-passwd-file-from-being-copy/m-p/2456854#M12776</link>
      <description>Hi Andreas,&lt;BR /&gt;&lt;BR /&gt;It works in ver 10.20 but not in 11.00. Does it required any patches ?</description>
      <pubDate>Tue, 24 Oct 2000 08:10:16 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/prevent-passwd-file-from-being-copy/m-p/2456854#M12776</guid>
      <dc:creator>yc_2</dc:creator>
      <dc:date>2000-10-24T08:10:16Z</dc:date>
    </item>
    <item>
      <title>Re: Prevent passwd file from being copy</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/prevent-passwd-file-from-being-copy/m-p/2456855#M12777</link>
      <description>Hi,&lt;BR /&gt;&lt;BR /&gt;on HP-UX 11.00 use instead -l -L:&lt;BR /&gt;ftp stream tcp nowait root /usr/lbin/ftpd ftpd -L -v&lt;BR /&gt;&lt;BR /&gt;Regards</description>
      <pubDate>Tue, 24 Oct 2000 08:18:04 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/prevent-passwd-file-from-being-copy/m-p/2456855#M12777</guid>
      <dc:creator>Andreas Voss</dc:creator>
      <dc:date>2000-10-24T08:18:04Z</dc:date>
    </item>
    <item>
      <title>Re: Prevent passwd file from being copy</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/prevent-passwd-file-from-being-copy/m-p/2456856#M12778</link>
      <description>Leong,&lt;BR /&gt;&lt;BR /&gt;At HP-UX 11, a new version of ftp was released, which includes a config file called /etc/ftpd/ftpaccess that allows you to both deny ftp access to /etc/passwd and log all files uploaded and downloaded from your server.  Here's what you need to do:&lt;BR /&gt;&lt;BR /&gt;1) Add a "-a" to the end of the ftp line in /etc/inetd.conf.&lt;BR /&gt;&lt;BR /&gt;2) Force inetd to re-read it's config file: inetd -c&lt;BR /&gt;&lt;BR /&gt;3) Create the /etc/ftpd/ftpaccess file with the following lines:&lt;BR /&gt;&lt;BR /&gt;class everyone real,guest,anonymous *&lt;BR /&gt;noretrieve /etc/passwd&lt;BR /&gt;log transfers anonymous,guest,real inbound,outbound&lt;BR /&gt;log commands anonymous,guest,real &lt;BR /&gt;&lt;BR /&gt;This will keep a log of all commands and files accessed via ftp.  The commands are logged in /var/adm/syslog/syslog.log, and the files, I think, are logged in /var/adm/syslog/xferlog.&lt;BR /&gt;&lt;BR /&gt;There is much more you can do in ftpaccess.  For more information, see the man page for ftpaccess and ftpd.  Also take a look at the sample ftpaccess file in /usr/newconfig/etc/ftpd/ftpaccess.&lt;BR /&gt;&lt;BR /&gt;Hope that helps!&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;both of the</description>
      <pubDate>Wed, 25 Oct 2000 21:35:51 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/prevent-passwd-file-from-being-copy/m-p/2456856#M12778</guid>
      <dc:creator>Darren Miller</dc:creator>
      <dc:date>2000-10-25T21:35:51Z</dc:date>
    </item>
  </channel>
</rss>

