<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic How to see unauthorized intrusion into Hp boxes in Operating System - HP-UX</title>
    <link>https://community.hpe.com/t5/operating-system-hp-ux/how-to-see-unauthorized-intrusion-into-hp-boxes/m-p/4016137#M299407</link>
    <description>We have 2 Itaniums rx 8640 and 2 Hp rx 7420, my DBA tells me he feels someone shutdown some services on the Oracle e-business suite ERP application this morning. How can we check to find out ?&lt;BR /&gt;Thanks</description>
    <pubDate>Fri, 08 Jun 2007 07:44:04 GMT</pubDate>
    <dc:creator>Yusuf Yila</dc:creator>
    <dc:date>2007-06-08T07:44:04Z</dc:date>
    <item>
      <title>How to see unauthorized intrusion into Hp boxes</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/how-to-see-unauthorized-intrusion-into-hp-boxes/m-p/4016137#M299407</link>
      <description>We have 2 Itaniums rx 8640 and 2 Hp rx 7420, my DBA tells me he feels someone shutdown some services on the Oracle e-business suite ERP application this morning. How can we check to find out ?&lt;BR /&gt;Thanks</description>
      <pubDate>Fri, 08 Jun 2007 07:44:04 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/how-to-see-unauthorized-intrusion-into-hp-boxes/m-p/4016137#M299407</guid>
      <dc:creator>Yusuf Yila</dc:creator>
      <dc:date>2007-06-08T07:44:04Z</dc:date>
    </item>
    <item>
      <title>Re: How to see unauthorized intrusion into Hp boxes</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/how-to-see-unauthorized-intrusion-into-hp-boxes/m-p/4016138#M299408</link>
      <description>Shalom,&lt;BR /&gt;&lt;BR /&gt;logs:&lt;BR /&gt;&lt;BR /&gt;/var/adm/syslog/syslog.log&lt;BR /&gt;&lt;BR /&gt;That and the keyboard histories should start the investigation.&lt;BR /&gt;&lt;BR /&gt;Ask the DBA for screen shots or logs with evidence. An oracle defect or missing OS patches could just as easily have caused this.&lt;BR /&gt;&lt;BR /&gt;SEP</description>
      <pubDate>Fri, 08 Jun 2007 07:47:04 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/how-to-see-unauthorized-intrusion-into-hp-boxes/m-p/4016138#M299408</guid>
      <dc:creator>Steven E. Protter</dc:creator>
      <dc:date>2007-06-08T07:47:04Z</dc:date>
    </item>
    <item>
      <title>Re: How to see unauthorized intrusion into Hp boxes</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/how-to-see-unauthorized-intrusion-into-hp-boxes/m-p/4016139#M299409</link>
      <description>Shalom,&lt;BR /&gt;&lt;BR /&gt;Sorry I forgot. For the next intrusion this software might be helpful.&lt;BR /&gt;&lt;BR /&gt;&lt;A href="http://h20293.www2.hp.com/portal/swdepot/displayProductInfo.do?productNumber=HPUX-HIDS" target="_blank"&gt;http://h20293.www2.hp.com/portal/swdepot/displayProductInfo.do?productNumber=HPUX-HIDS&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;Also, now that I actually use two brain cells at the same time, I'd say reset the passwords on all the oracle binary owners and be careful handing them out. &lt;BR /&gt;&lt;BR /&gt;Since its an oracle shutdown the oracle logs are the best place to look.&lt;BR /&gt;&lt;BR /&gt;SEP</description>
      <pubDate>Fri, 08 Jun 2007 07:49:33 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/how-to-see-unauthorized-intrusion-into-hp-boxes/m-p/4016139#M299409</guid>
      <dc:creator>Steven E. Protter</dc:creator>
      <dc:date>2007-06-08T07:49:33Z</dc:date>
    </item>
    <item>
      <title>Re: How to see unauthorized intrusion into Hp boxes</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/how-to-see-unauthorized-intrusion-into-hp-boxes/m-p/4016140#M299410</link>
      <description>syslog does not contain any meaninful information. Th elast login by root is not even logged there. Is it possible that it is not turned on ?</description>
      <pubDate>Fri, 08 Jun 2007 08:08:01 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/how-to-see-unauthorized-intrusion-into-hp-boxes/m-p/4016140#M299410</guid>
      <dc:creator>Yusuf Yila</dc:creator>
      <dc:date>2007-06-08T08:08:01Z</dc:date>
    </item>
    <item>
      <title>Re: How to see unauthorized intrusion into Hp boxes</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/how-to-see-unauthorized-intrusion-into-hp-boxes/m-p/4016141#M299411</link>
      <description>Hey&lt;BR /&gt;&lt;BR /&gt;check with "last" whether there is a machine of a user who shouldn't be able to login, someone perhaps know the root, oracle etc.. password.&lt;BR /&gt;&lt;BR /&gt;Regards</description>
      <pubDate>Fri, 08 Jun 2007 08:15:21 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/how-to-see-unauthorized-intrusion-into-hp-boxes/m-p/4016141#M299411</guid>
      <dc:creator>Oviwan</dc:creator>
      <dc:date>2007-06-08T08:15:21Z</dc:date>
    </item>
    <item>
      <title>Re: How to see unauthorized intrusion into Hp boxes</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/how-to-see-unauthorized-intrusion-into-hp-boxes/m-p/4016142#M299412</link>
      <description>Hi Yusuf&lt;BR /&gt;&lt;BR /&gt;There are two possibilities. The first most unlikely is that they did this remotely. Looking at the tnslistner log will be a good start. But I agree with Steve that it would in most likely be something in a log file as Oracle are pretty verbose when it comes to logging these sort of things.&lt;BR /&gt;&lt;BR /&gt;The other less likely option is that they logged on to the local servers to do this, but since it is 4 different servers unless your passwords are the same on all servers (no comment) this is unlikely. but you can use the last command to verify this. Also the sulog.&lt;BR /&gt;&lt;BR /&gt;Regards&lt;BR /&gt;&lt;BR /&gt;Andrew Y</description>
      <pubDate>Fri, 08 Jun 2007 08:19:20 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/how-to-see-unauthorized-intrusion-into-hp-boxes/m-p/4016142#M299412</guid>
      <dc:creator>Andrew Young_2</dc:creator>
      <dc:date>2007-06-08T08:19:20Z</dc:date>
    </item>
    <item>
      <title>Re: How to see unauthorized intrusion into Hp boxes</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/how-to-see-unauthorized-intrusion-into-hp-boxes/m-p/4016143#M299413</link>
      <description>Hello,&lt;BR /&gt;&lt;BR /&gt;The following pathnames are based on Oracle 9i, so YMMV:&lt;BR /&gt;&lt;BR /&gt;# who -u&lt;BR /&gt;to see who is currently logged in&lt;BR /&gt;&lt;BR /&gt;# last -R -100&lt;BR /&gt;to see the last 100 valid logins&lt;BR /&gt;&lt;BR /&gt;# lastb -R -100&lt;BR /&gt;to see the last 100 failed login attempts&lt;BR /&gt;&lt;BR /&gt;# more /home/oracle/.sh_history&lt;BR /&gt;to view the command history for the oracle user (obviously, substitute the appropriate username for your system)&lt;BR /&gt;&lt;BR /&gt;$ more ${ORACLE_BASE}/admin/&lt;SID&gt;/bdump/alert_&lt;SID&gt;.log&lt;BR /&gt;to view the alertlog for &lt;SID&gt;&lt;BR /&gt;&lt;BR /&gt;$ more ${ORACLE_HOME}/network/log/listener.log&lt;BR /&gt;to view connection history of Oracle listener&lt;BR /&gt;&lt;BR /&gt;# find / -type f -mtime -1 -print&lt;BR /&gt;for a list of recently modified files on your system&lt;BR /&gt;&lt;BR /&gt;PCS&lt;/SID&gt;&lt;/SID&gt;&lt;/SID&gt;</description>
      <pubDate>Fri, 08 Jun 2007 08:21:34 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/how-to-see-unauthorized-intrusion-into-hp-boxes/m-p/4016143#M299413</guid>
      <dc:creator>spex</dc:creator>
      <dc:date>2007-06-08T08:21:34Z</dc:date>
    </item>
    <item>
      <title>Re: How to see unauthorized intrusion into Hp boxes</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/how-to-see-unauthorized-intrusion-into-hp-boxes/m-p/4016144#M299414</link>
      <description>Thanks, i would try and get back to you.</description>
      <pubDate>Fri, 08 Jun 2007 09:30:08 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/how-to-see-unauthorized-intrusion-into-hp-boxes/m-p/4016144#M299414</guid>
      <dc:creator>Yusuf Yila</dc:creator>
      <dc:date>2007-06-08T09:30:08Z</dc:date>
    </item>
    <item>
      <title>Re: How to see unauthorized intrusion into Hp boxes</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/how-to-see-unauthorized-intrusion-into-hp-boxes/m-p/4016145#M299415</link>
      <description>What services does the dba feel where shutdown? What happened that lead him to infer this?</description>
      <pubDate>Fri, 08 Jun 2007 09:38:19 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/how-to-see-unauthorized-intrusion-into-hp-boxes/m-p/4016145#M299415</guid>
      <dc:creator>Court Campbell</dc:creator>
      <dc:date>2007-06-08T09:38:19Z</dc:date>
    </item>
  </channel>
</rss>

