<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: security in Operating System - HP-UX</title>
    <link>https://community.hpe.com/t5/operating-system-hp-ux/security/m-p/3487586#M214364</link>
    <description>kholikt,&lt;BR /&gt;thanks for 10 points, but I would really like to know&lt;BR /&gt;why would you recommend not installing IPFilter for&lt;BR /&gt;better security. I have been working for&lt;BR /&gt;Hewlett-Packard's IPFilter team for last few years and&lt;BR /&gt;you are the first person I have seen who is &lt;BR /&gt;recommending to avoid installing IPFilter and would&lt;BR /&gt;really like to know what I'm missing here.&lt;BR /&gt;&lt;BR /&gt;- Biswajit&lt;BR /&gt;</description>
    <pubDate>Fri, 18 Feb 2005 03:39:49 GMT</pubDate>
    <dc:creator>Biswajit Tripathy</dc:creator>
    <dc:date>2005-02-18T03:39:49Z</dc:date>
    <item>
      <title>security</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/security/m-p/3487578#M214356</link>
      <description>Hi,&lt;BR /&gt;&lt;BR /&gt;I am writing some security document.  I need to put some recommendation about the software selection during the OS installation.&lt;BR /&gt;&lt;BR /&gt;At this moment, the following components are recommended not to install.&lt;BR /&gt;&lt;BR /&gt;- CIFS related components including server and client&lt;BR /&gt;- Apache - if the server is not a web server&lt;BR /&gt;- NFS related components including server and client&lt;BR /&gt;- Tomcat&lt;BR /&gt;- XML Web server tools&lt;BR /&gt;- Webmin based admin&lt;BR /&gt;- Mozilla&lt;BR /&gt;- Ximian GNOME&lt;BR /&gt;- Java &lt;BR /&gt;- IPFilter&lt;BR /&gt;&lt;BR /&gt;Is there anything that I missed here.  This document based on HP-UX 11.23 and 11.11</description>
      <pubDate>Wed, 16 Feb 2005 21:20:08 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/security/m-p/3487578#M214356</guid>
      <dc:creator>kholikt</dc:creator>
      <dc:date>2005-02-16T21:20:08Z</dc:date>
    </item>
    <item>
      <title>Re: security</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/security/m-p/3487579#M214357</link>
      <description>I think You should rather include IPFilter, I am aware there are issues like local port redirection, but a malicious user could use a socks proxy etc. for that and the benefit of having IPFilter at hand can be great.&lt;BR /&gt;&lt;BR /&gt;CDE / X -  having a history of security issues, so You could leave them out in case no graphical logins are needed. (And for such cases, there are still other solutions)&lt;BR /&gt;&lt;BR /&gt;VxVm administrator - at least on Tru64 (LSM there) it listens on the network for some funky Java GUI.</description>
      <pubDate>Wed, 16 Feb 2005 21:31:25 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/security/m-p/3487579#M214357</guid>
      <dc:creator>Florian Heigl (new acc)</dc:creator>
      <dc:date>2005-02-16T21:31:25Z</dc:date>
    </item>
    <item>
      <title>Re: security</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/security/m-p/3487580#M214358</link>
      <description>If you will not use it, perhaps delete sendmail and the printing software.&lt;BR /&gt; I don't remember how isolated those filesets are.  Other candidates:  kermit, telnet, ftp, r-services.  &lt;BR /&gt;&lt;BR /&gt;Sorry I can't remember fileset names and the like.&lt;BR /&gt;&lt;BR /&gt;HTH,&lt;BR /&gt;Mic&lt;BR /&gt;</description>
      <pubDate>Wed, 16 Feb 2005 23:38:13 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/security/m-p/3487580#M214358</guid>
      <dc:creator>Mic V.</dc:creator>
      <dc:date>2005-02-16T23:38:13Z</dc:date>
    </item>
    <item>
      <title>Re: security</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/security/m-p/3487581#M214359</link>
      <description>You are recommending not to install IPFilter for better&lt;BR /&gt;security? Could you explain why?&lt;BR /&gt;&lt;BR /&gt;Don;t you think it would be easier to install IPFilter and&lt;BR /&gt;and allow only those incoming/outgoing traffic that you&lt;BR /&gt;want to allow and block everything else (and log all &lt;BR /&gt;suspicious connection attempts)? I can understand&lt;BR /&gt;that you don't want to install anything that is not &lt;BR /&gt;needed on the system, but IPFilter would add another&lt;BR /&gt;line of defence to your systems.&lt;BR /&gt;&lt;BR /&gt;- Biswajit&lt;BR /&gt;</description>
      <pubDate>Wed, 16 Feb 2005 23:53:38 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/security/m-p/3487581#M214359</guid>
      <dc:creator>Biswajit Tripathy</dc:creator>
      <dc:date>2005-02-16T23:53:38Z</dc:date>
    </item>
    <item>
      <title>Re: security</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/security/m-p/3487582#M214360</link>
      <description>Surf on over to &lt;A href="http://www.cisecurity.org/" target="_blank"&gt;http://www.cisecurity.org/&lt;/A&gt;&lt;BR /&gt;They provide various documents containing "Benchmark" security recommendations for various OS flavours, including HP-UX.</description>
      <pubDate>Thu, 17 Feb 2005 09:50:32 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/security/m-p/3487582#M214360</guid>
      <dc:creator>Gordon  Morrison</dc:creator>
      <dc:date>2005-02-17T09:50:32Z</dc:date>
    </item>
    <item>
      <title>Re: security</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/security/m-p/3487583#M214361</link>
      <description>uucp and related things are also candites to get rid of at the beginning, but they're no fileset of their own.</description>
      <pubDate>Thu, 17 Feb 2005 10:15:48 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/security/m-p/3487583#M214361</guid>
      <dc:creator>Florian Heigl (new acc)</dc:creator>
      <dc:date>2005-02-17T10:15:48Z</dc:date>
    </item>
    <item>
      <title>Re: security</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/security/m-p/3487584#M214362</link>
      <description>First read some doc about Bastion host &lt;BR /&gt;it will desc all  unsec software and way to exclude from install.&lt;BR /&gt;Install Bastion host &lt;BR /&gt;Install IPFILTER &lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Thu, 17 Feb 2005 12:20:26 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/security/m-p/3487584#M214362</guid>
      <dc:creator>Ivajlo Yanakiev</dc:creator>
      <dc:date>2005-02-17T12:20:26Z</dc:date>
    </item>
    <item>
      <title>Re: security</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/security/m-p/3487585#M214363</link>
      <description>CIFS related components including server and client:&lt;BR /&gt;Only install it if you need it. It is very useful if you want to share files on the HP box with windows users or vice versa. Otherwise its pretty much wasted hard disk space. It does not as far as I know represent a security hazard.&lt;BR /&gt;&lt;BR /&gt;NFS - Data goes back and forth in clear text. This is a security hazard. If you don't need NFS, don't use it. You must however leave it installed. I monkeyed around with removing it once and did serious damage to an old box I was using for the experiement. I ended up having to do an Ignite restore.&lt;BR /&gt;&lt;BR /&gt;Apache - significant issues. Right now I have a seemingly pointless port 80 abuse on my Linux Apache server and its driving me crazy, since I'm 7,000 miles from the box and must tread lightly.&lt;BR /&gt;&lt;BR /&gt;Tomcat: If the box is not a web server tomcat provides no functionality.&lt;BR /&gt;&lt;BR /&gt;Webmin based admin. I think for this you need apache running. There are no security hazards in this product that I know of, and its actually quite useful.&lt;BR /&gt;&lt;BR /&gt;XML - No web server, no need for these.&lt;BR /&gt;&lt;BR /&gt;Mozilla - Very useful, pretty secure. I use it to get patches so there is zero chance of me ruining the depot by forgetting to ftp the thing right from my pc. Also, the ftp step transmits passwords in clear text. Bad idea.&lt;BR /&gt;&lt;BR /&gt;Ximian GNOME - Dead product, no support any more. Decided not to go to Gnome. Their port was nice, but old.  It was patched a lot and there may have been security hazards.&lt;BR /&gt;&lt;BR /&gt;Java - Oracle needs it. Mozilla needs it. I'd think about changing my mind.&lt;BR /&gt;&lt;BR /&gt;IPfilter - No security hazards. Easy to use, can be helpful in improving security. I'd reconsider this one unless you trust each and every user BEHIND your firewall. Remember 65% of system attacks come from employees.&lt;BR /&gt;&lt;BR /&gt;General rule on security is: If its not going to be used, don't install it. It can not be abused if it does not exist on the system.&lt;BR /&gt;&lt;BR /&gt;SEP</description>
      <pubDate>Thu, 17 Feb 2005 12:35:14 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/security/m-p/3487585#M214363</guid>
      <dc:creator>Steven E. Protter</dc:creator>
      <dc:date>2005-02-17T12:35:14Z</dc:date>
    </item>
    <item>
      <title>Re: security</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/security/m-p/3487586#M214364</link>
      <description>kholikt,&lt;BR /&gt;thanks for 10 points, but I would really like to know&lt;BR /&gt;why would you recommend not installing IPFilter for&lt;BR /&gt;better security. I have been working for&lt;BR /&gt;Hewlett-Packard's IPFilter team for last few years and&lt;BR /&gt;you are the first person I have seen who is &lt;BR /&gt;recommending to avoid installing IPFilter and would&lt;BR /&gt;really like to know what I'm missing here.&lt;BR /&gt;&lt;BR /&gt;- Biswajit&lt;BR /&gt;</description>
      <pubDate>Fri, 18 Feb 2005 03:39:49 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/security/m-p/3487586#M214364</guid>
      <dc:creator>Biswajit Tripathy</dc:creator>
      <dc:date>2005-02-18T03:39:49Z</dc:date>
    </item>
  </channel>
</rss>

