<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: unknown user-id login count limit in Operating System - HP-UX</title>
    <link>https://community.hpe.com/t5/operating-system-hp-ux/unknown-user-id-login-count-limit/m-p/3067002#M139828</link>
    <description>I think the problem here is what are you going to do when you reach this limit?  Are you going to stop putting a "login" message on the screen, are you going to disable the terminal.&lt;BR /&gt;&lt;BR /&gt;I don't think you can do what you are asking here simply because I'm not sure there isn't much you can do with the information, you can't lock the account because there isn't one and you can't log them out as they aren't logged in.&lt;BR /&gt;&lt;BR /&gt;I may be missing something obvious though.</description>
    <pubDate>Tue, 09 Sep 2003 15:55:15 GMT</pubDate>
    <dc:creator>Mark Grant</dc:creator>
    <dc:date>2003-09-09T15:55:15Z</dc:date>
    <item>
      <title>unknown user-id login count limit</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/unknown-user-id-login-count-limit/m-p/3067000#M139826</link>
      <description>Is there a way to set a limit on the number of times an unknown user-id (does not exist) tries to log in?  Similiar to the failed login count for a known user-id...&lt;BR /&gt;&lt;BR /&gt;Thank you!&lt;BR /&gt;Melody</description>
      <pubDate>Tue, 09 Sep 2003 15:48:13 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/unknown-user-id-login-count-limit/m-p/3067000#M139826</guid>
      <dc:creator>Melody Pulling</dc:creator>
      <dc:date>2003-09-09T15:48:13Z</dc:date>
    </item>
    <item>
      <title>Re: unknown user-id login count limit</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/unknown-user-id-login-count-limit/m-p/3067001#M139827</link>
      <description>You should not let an unknown user log in at all, but her goes.&lt;BR /&gt;&lt;BR /&gt;Find out what ip address they are logging into.&lt;BR /&gt;&lt;BR /&gt;inetd -l&lt;BR /&gt;&lt;BR /&gt;That will enhance logging.&lt;BR /&gt;&lt;BR /&gt;look at /var/adm/syslog/syslog.log&lt;BR /&gt;&lt;BR /&gt;Then create or modify a file called &lt;BR /&gt;&lt;BR /&gt;/var/adm/inetd.sec&lt;BR /&gt;&lt;BR /&gt;Block access to that IP address.&lt;BR /&gt;&lt;BR /&gt;I'm attaching my file so you can see the syntax.  It has been purified.&lt;BR /&gt;&lt;BR /&gt;SEP</description>
      <pubDate>Tue, 09 Sep 2003 15:55:07 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/unknown-user-id-login-count-limit/m-p/3067001#M139827</guid>
      <dc:creator>Steven E. Protter</dc:creator>
      <dc:date>2003-09-09T15:55:07Z</dc:date>
    </item>
    <item>
      <title>Re: unknown user-id login count limit</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/unknown-user-id-login-count-limit/m-p/3067002#M139828</link>
      <description>I think the problem here is what are you going to do when you reach this limit?  Are you going to stop putting a "login" message on the screen, are you going to disable the terminal.&lt;BR /&gt;&lt;BR /&gt;I don't think you can do what you are asking here simply because I'm not sure there isn't much you can do with the information, you can't lock the account because there isn't one and you can't log them out as they aren't logged in.&lt;BR /&gt;&lt;BR /&gt;I may be missing something obvious though.</description>
      <pubDate>Tue, 09 Sep 2003 15:55:15 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/unknown-user-id-login-count-limit/m-p/3067002#M139828</guid>
      <dc:creator>Mark Grant</dc:creator>
      <dc:date>2003-09-09T15:55:15Z</dc:date>
    </item>
    <item>
      <title>Re: unknown user-id login count limit</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/unknown-user-id-login-count-limit/m-p/3067003#M139829</link>
      <description>Melody,&lt;BR /&gt;&lt;BR /&gt;If it's an unknown user id (by this I assume you mean that it does not exist in the password file/database), then it never gets logged in - why would you care?&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Pete&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Tue, 09 Sep 2003 15:56:15 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/unknown-user-id-login-count-limit/m-p/3067003#M139829</guid>
      <dc:creator>Pete Randall</dc:creator>
      <dc:date>2003-09-09T15:56:15Z</dc:date>
    </item>
    <item>
      <title>Re: unknown user-id login count limit</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/unknown-user-id-login-count-limit/m-p/3067004#M139830</link>
      <description>Sorry for any confusion.  We are trying to address an audit item. Urf, I didn't state the "why" and "result" we are looking for.  Should an unknown user-id (does not exist in passwd file) try to log in more than 3 times, say via telnet, their telnet session should be terminated.  The default seems to be 10 failed attempts before their session is terminated.&lt;BR /&gt;&lt;BR /&gt;For a known user we have it set to 3 failed attempts but the result is that their account is then locked.&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Tue, 09 Sep 2003 16:14:03 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/unknown-user-id-login-count-limit/m-p/3067004#M139830</guid>
      <dc:creator>Melody Pulling</dc:creator>
      <dc:date>2003-09-09T16:14:03Z</dc:date>
    </item>
    <item>
      <title>Re: unknown user-id login count limit</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/unknown-user-id-login-count-limit/m-p/3067005#M139831</link>
      <description>This is going to be really tough. You may be able to get the info  from the syslog but you somehow have got to get the "login" program to do the counting,  Then you have to kill the associated telnetd which might be a bit tricky too because you can't key on ip address as there might be several people using the same ip address to telnet to you some of whom may be legit.&lt;BR /&gt;&lt;BR /&gt;The only way I can see this being possible is to write your own "login".&lt;BR /&gt;&lt;BR /&gt;To be honest, what's the point anyway, you can kill the telnet session but that doesn't stop them telnetting right back to you.</description>
      <pubDate>Tue, 09 Sep 2003 16:26:49 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/unknown-user-id-login-count-limit/m-p/3067005#M139831</guid>
      <dc:creator>Mark Grant</dc:creator>
      <dc:date>2003-09-09T16:26:49Z</dc:date>
    </item>
    <item>
      <title>Re: unknown user-id login count limit</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/unknown-user-id-login-count-limit/m-p/3067006#M139832</link>
      <description>Thank you ALL very much for your time and replies.&lt;BR /&gt;&lt;BR /&gt;Mark,&lt;BR /&gt;&lt;BR /&gt;Thank you!  That is what I thought but had to confirm it for our auditing department. &lt;BR /&gt;&lt;BR /&gt;:-)&lt;BR /&gt;&lt;BR /&gt;Have a great day.&lt;BR /&gt;Melody</description>
      <pubDate>Tue, 09 Sep 2003 16:38:19 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/unknown-user-id-login-count-limit/m-p/3067006#M139832</guid>
      <dc:creator>Melody Pulling</dc:creator>
      <dc:date>2003-09-09T16:38:19Z</dc:date>
    </item>
  </channel>
</rss>

